Darkhotel — APT Profile
Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select guests. Darkhotel has also conducted spearphishing campaigns and infected victims through peer-to-peer and file sharing networks.Also tracked as
DUBNIUM, Zigzag Hail
Vendor research
- How Microsoft names threat actors Microsoft
- Microsoft Digital Defense Report FY20 Microsoft
- Reverse engineering DUBNIUM – Stage 2 payload analysis Microsoft
- Reverse-engineering DUBNIUM’s Flash-targeting exploit Microsoft
- Reverse-engineering DUBNIUM Microsoft
- Darkhotel's attacks in 2015 Securelist
- Microsoft Digital Defense Report FY20 Microsoft
- The Darkhotel APT A Story of Unusual Hospitality Kaspersky