← threatfilter.dev / all groups / Darkhotel
Darkhotel
Also known as: DUBNIUM · Zigzag Hail
Overview
Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select guests. Darkhotel has also conducted spearphishing campaigns and infected victims through peer-to-peer and file sharing networks.
Targets
Private sector
Regions
China · Japan · Russia · South Korea · Taiwan
Capabilities
- Exploitation of public-facing / client applications — ATT&CK T1203
TTPs — 24 techniques across 9 tactics
Initial Access
-
T1189Drive-by Compromise -
T1566.001Spearphishing Attachment
Execution
-
T1059.003Windows Command Shell -
T1203Exploitation for Client Execution -
T1204.002Malicious File
Persistence
-
T1547.001Registry Run Keys / Startup Folder
Stealth
-
T1027.013Encrypted/Encoded File -
T1036.005Match Legitimate Resource Name or Location -
T1140Deobfuscate/Decode Files or Information -
T1497Virtualization/Sandbox Evasion -
T1497.001System Checks -
T1497.002User Activity Based Checks
Defense Impairment
-
T1553.002Code Signing
Discovery
-
T1016System Network Configuration Discovery -
T1057Process Discovery -
T1082System Information Discovery -
T1083File and Directory Discovery -
T1124System Time Discovery -
T1518.001Security Software Discovery
Lateral Movement
Collection
-
T1056.001Keylogging
Command and Control
-
T1105Ingress Tool Transfer -
T1573.001Symmetric Cryptography
Reporting (3)
- How Microsoft names threat actors — Microsoft
- Microsoft Digital Defense Report FY20 — Microsoft
- Reverse engineering DUBNIUM – Stage 2 payload analysis — Microsoft