Intrusion setG0012
Darkhotel
Also tracked as DUBNIUM, Zigzag Hail
Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select guests. Darkhotel has also conducted spearphishing campaigns and infected victims through peer-to-peer and file sharing networks.
- Documented techniques
- 24
- Assessed origin
- South Korea
- Assessed motivation
- Espionage
- First seen
- 2004
- Basis
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.