Darkhotel

MITRE ATT&CK: G0012 View on attack.mitre.org

Aliases: DUBNIUM, Zigzag Hail, Fallout Team, Karba, Luder, Nemim, Nemin, Tapaoux, Pioneer, Shadow Crane, APT-C-06, SIG25, TUNGSTEN BRIDGE, T-APT-02, ATK52, Darkhotel, darkhotel, Dark Hotel, SHADOW CRANE, TEMPLAR, TieOnJoe, Purple Pygmy, Egobot, PALADIN, APT-C-60

First seen
2004-01-01 00:00:00
Origin
KR
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Related IoCs
121 (119 malicious)
Last IoC activity
2026-09-02 00:38:30
Profile updated
2026-07-07 12:34:45

Targeted industries: government-and-public-sector professional-services retail-and-hospitality technology-and-telecommunications

Targeted regions: country_code:kr country_code:jp country_code:cn country_code:us

Context

Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select guests. Darkhotel has also conducted spearphishing campaigns and infected victims through peer-to-peer and file sharing networks.

Recent IoC activity

119 malicious indicators in Maltiverse are attributed to Darkhotel (G0012). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname www.nullsecurity.net 2026-09-03 1
hostname ns-3.open.ro 2026-09-03 1
hostname autodiscover.email 2026-09-03 1
hostname autodiscover.exchange 2026-09-03 1
hostname autoconfig.email 2026-09-03 1
hostname mail.pics 2026-09-03 1
hostname prod.tools 2026-09-02 1
hostname webdisk.us 2026-09-02 1
hostname autodiscover.host 2026-09-02 1
hostname admin.dev 2026-09-02 1
hostname autodiscover.it 2026-09-02 1
hostname made.by 2026-09-02 1
hostname www.cantrip.org 2026-09-02 1
hostname test.support 2026-09-02 1
hostname mail.news 2026-09-02 1
hostname webdisk.it 2026-09-02 1
hostname webdisk.de 2026-09-02 1
hostname autodiscover.online 2026-09-02 1
hostname secure.dev 2026-09-02 1
hostname autodiscover.de 2026-09-02 1

Detection coverage

  • 310 Sigma rules

Malware & tools used

  • User Activity Based Checks (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Taint Shared Content (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Keylogging (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Process Discovery (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • Replication Through Removable Media (attack-pattern)
  • Virtualization/Sandbox Evasion (attack-pattern)
  • System Checks (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Code Signing (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • Malicious File (attack-pattern)
  • Security Software Discovery (attack-pattern)

Reports & references

  • Kaspersky — Darkhotels Attacks In 2015 (report)
  • Microsoft — Reverse Engineering Dubnium 2 (report)
  • Kaspersky — The Darkhotel Apt (report)
  • Kaspersky — 66779 (report)
  • web.archive.org — 11726 (report)
  • labs.bitdefender.com — Inexsmar An Unusual Darkhotel Campaign (report)
  • cfr.org — Darkhotel (report)
  • securityweek.com — Darkhotel Apt Uses New Methods Target Politicians (report)
  • MITRE ATT&CK — G0012 (report)
  • secureworks.com — Tungsten Bridge (report)
  • antiy.cn — 20200522 (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • media.kasperskycontenthub.com — Darkhotel Kl 07.11 (report)
  • Microsoft — Rwxpuf (report)
  • Kaspersky — 71713 (report)
  • Microsoft — Reverse Engineering Dubnium 2 (report)
  • Microsoft — Reverse Engineering Dubniums Flash Targeting Exploit (report)
  • Microsoft — Reverse Engineering Dubnium Stage 2 Payload Analysis (report)
  • Microsoft — Reverse Engineering Dubniums Flash Targeting Exploit (report)
  • Microsoft — Reverse Engineering Dubnium Stage 2 Payload Analysis (report)

External references