🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
DARKHOTEL

/actor/darkhotel/  ·  0 intel reports

Year Established
2007
Attribution
South Korea (Suspected)
Motivation
Espionage, Corporate Intelligence
Modus Operandi (MO)
Hotel Wi-Fi attacks, spear-phishing senior executives, zero-day exploitation
Primary Aliases
Dubnium, TUNGSTEN BRIDGE, Karba, SIG25

DarkHotel is a sophisticated threat actor group attributed with moderate confidence to South Korean intelligence services, distinguished by its highly creative and patient targeting methodology: compromising the Wi-Fi networks of luxury hotels and business hotels across Asia to deliver malware to high-value executive guests during their stays. This "hotel Wi-Fi attack" technique gave the group its name and remains one of the most distinctive attack vectors attributed to any nation-state APT group.

The group's operational approach demonstrated exceptional intelligence preparation: DarkHotel operators would identify specific target executives planning to stay at particular hotels , via travel booking records, corporate itineraries, or open-source intelligence , and pre-position malware on those hotels' networks to intercept the specific target's device when they connected to the in-room Wi-Fi. This targeted precision, combined with the use of software update spoofing to trick executives into installing malicious "updates," demonstrated a level of operational sophistication far beyond typical cybercriminal activity.

Beyond the hotel Wi-Fi vector, DarkHotel conducts conventional spear-phishing campaigns against senior executives, board members, and C-suite officials at multinational corporations with operations in Asia. The group has exploited multiple Adobe Flash, Internet Explorer, and Windows zero-day vulnerabilities , a significant resource investment indicating state-level capability and motivation. Their targets span pharmaceutical, automotive, electronics, and defence manufacturing sectors.

DarkHotel has been active for nearly two decades, demonstrating exceptional operational longevity and adaptation. Their continued investment in zero-day exploitation and sophisticated targeting methodologies , including more recent campaigns using spear-phishing with COVID-19 pandemic lures against biomedical and pharmaceutical researchers , confirms an ongoing, well-resourced intelligence collection mandate showing no signs of diminishment.

Threat Mitigation and Strategic Hardening: Network defense against campaigns linked to DarkHotel requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our Cyber Risk Checker and report critical indicators via Secure Drop.

STATUS: ACTIVE CLASSIFICATION: STATE-SPONSORED (APT) LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles