Darkhotel
Also tracked as DUBNIUM, Zigzag Hail
Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select guests. Darkhotel has also conducted spearphishing campaigns and infected victims through peer-to-peer and file sharing networks.
- Known attack methods
- 24
- Origin
- South Korea
- Motive
- Espionage
- First seen
- 2004
- Source
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, mapped onto the ATT&CK matrix. Each one is a behaviour you can look for in your own logs, and a control you can test.
Reconnaissance
12 techniques
Resource Development
9 techniques
Initial Access
11 techniques · 2 used
Execution
20 techniques · 3 used
Persistence
22 techniques · 1 used
Privilege Escalation
13 techniques
Stealth
30 techniques · 4 used
Defense Impairment
18 techniques · 1 used
Credential Access
17 techniques
Discovery
34 techniques · 6 used
Lateral Movement
9 techniques · 2 used
Collection
17 techniques · 1 used
Command and Control
18 techniques · 2 used
Exfiltration
9 techniques
Impact
15 techniques