ATT&CKReferencesKaspersky Darkhotel

Kaspersky Darkhotel

Kaspersky Lab's Global Research and Analysis Team. (2014, November). The Darkhotel APT A Story of Unusual Hospitality. Retrieved November 12, 2014.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1056.001
Keylogging
GroupDarkhotel

Darkhotel has used a keylogger.

T1080
Taint Shared Content
GroupDarkhotel

Darkhotel used a virus that propagates by infecting executables stored on shared drives.

T1091
Replication Through Removable Media
GroupDarkhotel

Darkhotel's selective infector modifies executables stored on removable media as a method of spreading across computers.

T1189
Drive-by Compromise
GroupDarkhotel

Darkhotel used embedded iframes on hotel login portals to redirect selected victims to download malware.

T1547.001
Registry Run Keys / Startup Folder
GroupDarkhotel

Darkhotel has been known to establish persistence by adding programs to the Run Registry key.

T1553.002
Code Signing
GroupDarkhotel

Darkhotel has used code-signing certificates on its malware that are either forged due to weak keys or stolen. Darkhotel has also stolen certificates and signed backdoors and downloaders with them.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.