Threat group.View on attack.mitre.org
Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select guests. Darkhotel has also conducted spearphishing campaigns and infected victims through peer-to-peer and file sharing networks.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
Darkhotel has collected the IP address and network adapter information from the victim’s machine. |
| T1027.013 Encrypted/Encoded File |
Darkhotel has obfuscated code using RC4, XOR, and RSA. |
| T1036.005 Match Legitimate Resource Name or Location |
Darkhotel has used malware that is disguised as a Secure Shell (SSH) tool. |
| T1056.001 Keylogging |
Darkhotel has used a keylogger. |
| T1057 Process Discovery |
Darkhotel malware can collect a list of running processes on a system. |
| T1059.003 Windows Command Shell |
Darkhotel has dropped an mspaint.lnk shortcut to disk which launches a shell script that downloads and executes a file. |
| T1080 Taint Shared Content |
Darkhotel used a virus that propagates by infecting executables stored on shared drives. |
| T1082 System Information Discovery |
Darkhotel has collected the hostname, OS version, service pack version, and the processor architecture from the victim’s machine. |
| T1083 File and Directory Discovery |
Darkhotel has used malware that searched for files with specific patterns. |
| T1091 Replication Through Removable Media |
Darkhotel's selective infector modifies executables stored on removable media as a method of spreading across computers. |
| T1105 Ingress Tool Transfer |
Darkhotel has used first-stage payloads that download additional malware from C2 servers. |
| T1124 System Time Discovery |
Darkhotel malware can obtain system time from a compromised host. |
| T1140 Deobfuscate/Decode Files or Information |
Darkhotel has decrypted strings and imports using RC4 during execution. |
| T1189 Drive-by Compromise |
Darkhotel used embedded iframes on hotel login portals to redirect selected victims to download malware. |
| T1203 Exploitation for Client Execution |
Darkhotel has exploited Adobe Flash vulnerability CVE-2015-8651 for execution. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.