Darkhotel — APT Profile
Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select guests. Darkhotel has also conducted spearphishing campaigns and infected victims through peer-to-peer and file sharing networks.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
DUBNIUM, Zigzag Hail, Fallout Team, Karba, Luder, Nemim, Nemin, Tapaoux, Pioneer, Shadow Crane, APT-C-06, SIG25, TUNGSTEN BRIDGE, T-APT-02, G0012, ATK52
Vendor research
- How Microsoft names threat actors Microsoft
- Microsoft Digital Defense Report FY20 Microsoft
- Reverse engineering DUBNIUM – Stage 2 payload analysis Microsoft
- Reverse-engineering DUBNIUM’s Flash-targeting exploit Microsoft
- Reverse-engineering DUBNIUM Microsoft
- Darkhotel's attacks in 2015 Securelist
- Microsoft Digital Defense Report FY20 Microsoft
- The Darkhotel APT A Story of Unusual Hospitality Kaspersky