{"id":462,"count":0,"description":"<div class=\"actor-dossier\" style=\"display:flex;flex-wrap:wrap;gap:12px;margin-bottom:20px\">\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Year Established<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">2007<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Attribution<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">South Korea (Suspected)<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Motivation<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Espionage, Corporate Intelligence<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Modus Operandi (MO)<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Hotel Wi-Fi attacks, spear-phishing senior executives, zero-day exploitation<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Primary Aliases<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Dubnium, TUNGSTEN BRIDGE, Karba, SIG25<\/div>\n  <\/div>\n<\/div>\n<p>DarkHotel is a sophisticated threat actor group attributed with moderate confidence to South Korean intelligence services, distinguished by its highly creative and patient targeting methodology: compromising the Wi-Fi networks of luxury hotels and business hotels across Asia to deliver malware to high-value executive guests during their stays. This \"hotel Wi-Fi attack\" technique gave the group its name and remains one of the most distinctive attack vectors attributed to any nation-state APT group.<\/p>\n<p>The group's operational approach demonstrated exceptional intelligence preparation: DarkHotel operators would identify specific target executives planning to stay at particular hotels ,  via travel booking records, corporate itineraries, or open-source intelligence ,  and pre-position malware on those hotels' networks to intercept the specific target's device when they connected to the in-room Wi-Fi. This targeted precision, combined with the use of software update spoofing to trick executives into installing malicious \"updates,\" demonstrated a level of operational sophistication far beyond typical cybercriminal activity.<\/p>\n<p>Beyond the hotel Wi-Fi vector, DarkHotel conducts conventional spear-phishing campaigns against senior executives, board members, and C-suite officials at multinational corporations with operations in Asia. The group has exploited multiple Adobe Flash, Internet Explorer, and Windows zero-day vulnerabilities ,  a significant resource investment indicating state-level capability and motivation. Their targets span pharmaceutical, automotive, electronics, and defence manufacturing sectors.<\/p>\n<p>DarkHotel has been active for nearly two decades, demonstrating exceptional operational longevity and adaptation. Their continued investment in zero-day exploitation and sophisticated targeting methodologies ,  including more recent campaigns using spear-phishing with COVID-19 pandemic lures against biomedical and pharmaceutical researchers ,  confirms an ongoing, well-resourced intelligence collection mandate showing no signs of diminishment.<\/p>\n\n<p><strong>Threat Mitigation and Strategic Hardening:<\/strong> Network defense against campaigns linked to <strong>DarkHotel<\/strong> requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our <a href=\"https:\/\/cyberasia.io\/cyber-risk-checker\/\" style=\"color: #facc15; text-decoration: none;\">Cyber Risk Checker<\/a> and report critical indicators via <a href=\"https:\/\/cyberasia.io\/secure-drop\/\" style=\"color: #facc15; text-decoration: none;\">Secure Drop<\/a>.<\/p>","link":"https:\/\/cyberasia.io\/actor\/darkhotel\/","name":"DarkHotel","slug":"darkhotel","taxonomy":"threat_actor","parent":0,"meta":[],"_links":{"self":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors\/462","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors"}],"about":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/taxonomies\/threat_actor"}],"wp:post_type":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts?threat_actors=462"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}