Kaspersky Lab's Global Research and Analysis Team. (2014, November). The Darkhotel APT A Story of Unusual Hospitality. Retrieved November 12, 2014.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.001 Keylogging |
GroupDarkhotel | Darkhotel has used a keylogger. |
| T1080 Taint Shared Content |
GroupDarkhotel | Darkhotel used a virus that propagates by infecting executables stored on shared drives. |
| T1091 Replication Through Removable Media |
GroupDarkhotel | Darkhotel's selective infector modifies executables stored on removable media as a method of spreading across computers. |
| T1189 Drive-by Compromise |
GroupDarkhotel | Darkhotel used embedded iframes on hotel login portals to redirect selected victims to download malware. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupDarkhotel | Darkhotel has been known to establish persistence by adding programs to the Run Registry key. |
| T1553.002 Code Signing |
GroupDarkhotel | Darkhotel has used code-signing certificates on its malware that are either forged due to weak keys or stolen. Darkhotel has also stolen certificates and signed backdoors and downloaders with them. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.