NEW: Group Profiler — instant APT intel lookup. Try it →

Darkhotel

G0012 South Korea Espionage MITRE ATT&CK →

Also known as: DUBNIUM · Zigzag Hail

Overview

Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select guests. Darkhotel has also conducted spearphishing campaigns and infected victims through peer-to-peer and file sharing networks.

Naming & attribution

Darkhotel is tracked under 3 names across the industry. It uses 24 documented ATT&CK techniques — more than 58% of the 174 groups tracked here. Activity attributed since at least 2004.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
DUBNIUMMicrosoft
Zigzag HailMicrosoft
DarkHotelKaspersky Lab's Global Research and Analysis Team

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1497.002 User Activity Based Checks — used by 2 of 174 groups
  • T1497 Virtualization/Sandbox Evasion — used by 3 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Sidewinder India — 13 shared techniques (32% overlap)
  • Tropic Trooper China — 15 shared techniques (31% overlap)
  • Higaisa South Korea — 12 shared techniques (30% overlap)
  • admin@338 China — 8 shared techniques (29% overlap)
  • BRONZE BUTLER China — 13 shared techniques (25% overlap)
  • Inception Russia — 9 shared techniques (24% overlap)

Targets

Private sector

Regions

China · Japan · Russia · South Korea · Taiwan

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1203

TTPs — 24 techniques across 9 tactics

Reporting (3)