Darkhotel
MITRE ATT&CK: G0012 View on attack.mitre.org
Aliases: DUBNIUM, Zigzag Hail, Fallout Team, Karba, Luder, Nemim, Nemin, Tapaoux, Pioneer, Shadow Crane, APT-C-06, SIG25, TUNGSTEN BRIDGE, T-APT-02, ATK52, Darkhotel, darkhotel, Dark Hotel, SHADOW CRANE, TEMPLAR, TieOnJoe, Purple Pygmy, Egobot, PALADIN, APT-C-60
- First seen
- 2004-01-01 00:00:00
- Origin
- KR
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Related IoCs
- 121 (119 malicious)
- Last IoC activity
- 2026-09-02 00:38:30
- Profile updated
- 2026-07-07 12:34:45
Targeted industries: government-and-public-sector professional-services retail-and-hospitality technology-and-telecommunications
Targeted regions: country_code:kr country_code:jp country_code:cn country_code:us
Context
Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select guests. Darkhotel has also conducted spearphishing campaigns and infected victims through peer-to-peer and file sharing networks.
Recent IoC activity
119 malicious indicators in Maltiverse are attributed to Darkhotel (G0012). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | www.nullsecurity.net | 2026-09-03 | 1 |
| hostname | ns-3.open.ro | 2026-09-03 | 1 |
| hostname | autodiscover.email | 2026-09-03 | 1 |
| hostname | autodiscover.exchange | 2026-09-03 | 1 |
| hostname | autoconfig.email | 2026-09-03 | 1 |
| hostname | mail.pics | 2026-09-03 | 1 |
| hostname | prod.tools | 2026-09-02 | 1 |
| hostname | webdisk.us | 2026-09-02 | 1 |
| hostname | autodiscover.host | 2026-09-02 | 1 |
| hostname | admin.dev | 2026-09-02 | 1 |
| hostname | autodiscover.it | 2026-09-02 | 1 |
| hostname | made.by | 2026-09-02 | 1 |
| hostname | www.cantrip.org | 2026-09-02 | 1 |
| hostname | test.support | 2026-09-02 | 1 |
| hostname | mail.news | 2026-09-02 | 1 |
| hostname | webdisk.it | 2026-09-02 | 1 |
| hostname | webdisk.de | 2026-09-02 | 1 |
| hostname | autodiscover.online | 2026-09-02 | 1 |
| hostname | secure.dev | 2026-09-02 | 1 |
| hostname | autodiscover.de | 2026-09-02 | 1 |
Detection coverage
- 310 Sigma rules
Malware & tools used
- User Activity Based Checks (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Taint Shared Content (attack-pattern)
- System Information Discovery (attack-pattern)
- Keylogging (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Process Discovery (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Drive-by Compromise (attack-pattern)
- Replication Through Removable Media (attack-pattern)
- Virtualization/Sandbox Evasion (attack-pattern)
- System Checks (attack-pattern)
- System Time Discovery (attack-pattern)
- Code Signing (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- Malicious File (attack-pattern)
- Security Software Discovery (attack-pattern)
Reports & references
- Kaspersky — Darkhotels Attacks In 2015 (report)
- Microsoft — Reverse Engineering Dubnium 2 (report)
- Kaspersky — The Darkhotel Apt (report)
- Kaspersky — 66779 (report)
- web.archive.org — 11726 (report)
- labs.bitdefender.com — Inexsmar An Unusual Darkhotel Campaign (report)
- cfr.org — Darkhotel (report)
- securityweek.com — Darkhotel Apt Uses New Methods Target Politicians (report)
- MITRE ATT&CK — G0012 (report)
- secureworks.com — Tungsten Bridge (report)
- antiy.cn — 20200522 (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- media.kasperskycontenthub.com — Darkhotel Kl 07.11 (report)
- Microsoft — Rwxpuf (report)
- Kaspersky — 71713 (report)
- Microsoft — Reverse Engineering Dubnium 2 (report)
- Microsoft — Reverse Engineering Dubniums Flash Targeting Exploit (report)
- Microsoft — Reverse Engineering Dubnium Stage 2 Payload Analysis (report)
- Microsoft — Reverse Engineering Dubniums Flash Targeting Exploit (report)
- Microsoft — Reverse Engineering Dubnium Stage 2 Payload Analysis (report)
External references
- mitre-attack — G0012
- Darkhotel
- DUBNIUM
- Zigzag Hail
- Securelist Darkhotel Aug 2015
- Kaspersky Darkhotel
- Microsoft Digital Defense FY20 Sept 2020
- Microsoft Threat Actor Naming July 2023
- Microsoft DUBNIUM July 2016
- Microsoft DUBNIUM Flash June 2016
- Microsoft DUBNIUM June 2016
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy