ATT&CKGroupsDarkhotel

Darkhotel

G0012

Threat group.View on attack.mitre.org

About this group

Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select guests. Darkhotel has also conducted spearphishing campaigns and infected victims through peer-to-peer and file sharing networks.

Techniques used24

Procedure examples24

TechniqueProcedure example
T1016
System Network Configuration Discovery

Darkhotel has collected the IP address and network adapter information from the victim’s machine.

T1027.013
Encrypted/Encoded File

Darkhotel has obfuscated code using RC4, XOR, and RSA.

T1036.005
Match Legitimate Resource Name or Location

Darkhotel has used malware that is disguised as a Secure Shell (SSH) tool.

T1056.001
Keylogging

Darkhotel has used a keylogger.

T1057
Process Discovery

Darkhotel malware can collect a list of running processes on a system.

T1059.003
Windows Command Shell

Darkhotel has dropped an mspaint.lnk shortcut to disk which launches a shell script that downloads and executes a file.

T1080
Taint Shared Content

Darkhotel used a virus that propagates by infecting executables stored on shared drives.

T1082
System Information Discovery

Darkhotel has collected the hostname, OS version, service pack version, and the processor architecture from the victim’s machine.

T1083
File and Directory Discovery

Darkhotel has used malware that searched for files with specific patterns.

T1091
Replication Through Removable Media

Darkhotel's selective infector modifies executables stored on removable media as a method of spreading across computers.

T1105
Ingress Tool Transfer

Darkhotel has used first-stage payloads that download additional malware from C2 servers.

T1124
System Time Discovery

Darkhotel malware can obtain system time from a compromised host.

T1140
Deobfuscate/Decode Files or Information

Darkhotel has decrypted strings and imports using RC4 during execution.

T1189
Drive-by Compromise

Darkhotel used embedded iframes on hotel login portals to redirect selected victims to download malware.

T1203
Exploitation for Client Execution

Darkhotel has exploited Adobe Flash vulnerability CVE-2015-8651 for execution.

View all 24 procedure examples

Software0

None recorded.

Campaigns0

None recorded.

References3

  1. Kaspersky Darkhotel Open source
    Kaspersky Lab's Global Research and Analysis Team. (2014, November). The Darkhotel APT A Story of Unusual Hospitality. Retrieved November 12, 2014.
  2. Microsoft Digital Defense FY20 Sept 2020 Open source
    Microsoft . (2020, September 29). Microsoft Digital Defense Report FY20. Retrieved April 21, 2021.
  3. Securelist Darkhotel Aug 2015 Open source
    Kaspersky Lab's Global Research & Analysis Team. (2015, August 10). Darkhotel's attacks in 2015. Retrieved November 2, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.