A South Korean-linked APT group known for targeting high-value travelers via hotel Wi-Fi networks using zero-day exploits.
Analyst brief
DarkHotel is a South Korean-linked nation-state actor that targets private-sector organizations primarily in East Asia. Their notable TTPs include Drive-by Compromise via hotel Wi-Fi networks, Spearphishing with high-end zero-day Flash exploits, and using Code Signing and Encrypted/Encoded Files to evade detection. The group also uses Windows Command Shell for execution, performs Security Software Discovery, and has a unique capability to track and hit targets as they travel. Defenders should implement strict network-level monitoring for traveling high-value users, scrutinize suspiciously signed binaries, and enforce a proactive patching policy against advanced spearphishing and zero-day exploitation attempts.
DarkHotel
DUBNIUMFallout TeamKarba
nation-state
Kaspersky described DarkHotel in a 2014 report as: '... DarkHotel drives its campaigns by spear-phishing targets with highly advanced Flash zero-day exploits that effectively evade the latest Windows and Adobe defenses, and yet they also imprecisely spread among large numbers of vague targets with peer-to-peer spreading tactics. Moreover, this crews most unusual characteristic is that for several years the Darkhotel APT has maintained a capability to use hotel networks to follow and hit selected targets as they travel around the world.'
origin (suspected)
🇰🇷Korea (Republic of)· state-sponsoredattribution confidence: medium (50)
What unique method does the DarkHotel actor use to track their traveling targets?+
DarkHotel uses hotel Wi-Fi networks to track and hit selected targets as they travel around the world.
What type of advanced exploit does DarkHotel utilize in their Spearphishing attacks?+
DarkHotel employs highly advanced Flash zero-day exploits in their Spearphishing attacks, which effectively evade the latest Windows and Adobe defenses.