Darkhotel

Threat Actor updated 5 months ago (2024-05-04T19:17:17.734Z)
Download STIX
Preview STIX
DarkHotel, also known as DUBNIUM, is a cyber threat actor that has been active since at least 2018. This group has been observed primarily targeting Japanese organizations and has recently been linked to a campaign utilizing unique Tactics, Techniques, and Procedures (TTPs). The campaign involved a multi-stage binary infection phase using home-brewed malware, demonstrating DarkHotel's advanced persistent threat attributes. Notably, the group has exploited software vulnerabilities alongside other Advanced Persistent Threat (APT) actors such as CactusPete, TwoSail Junk, FunnyDream, and others. Moreover, DarkHotel has been found to exploit the COVID-19 pandemic, much like other APT groups including Kimsuky and Hades. The analysis of this campaign revealed that DarkHotel used Ramsay’s version 2.a Spreader component, which reused a series of tokens previously seen in DarkHotel’s Retro Backdoor. This suggests significant technical overlaps between Ramsay and DarkHotel’s historical Trojans. Despite the risk of detection by antivirus software, DarkHotel's activities seem to be limited to specific targets, indicating a high degree of precision in their operations. This targeted approach, coupled with an improved malicious code infection technology, underscores the group's sophisticated attack process. DarkHotel's operations have been particularly prominent in Southeast Asia, a region noted for its high level of APT activity from established actors such as Lazarus, Kimsuky, and newer groups like Cloud Snooper and Fishing Elephant. Interestingly, despite the complexity of DarkHotel’s activities for isolation network penetration, their implementation cost is lower compared to more intricate systems like the A2PT seismograph. However, their transmission, infection, and exudation processes are heavily reliant on personnel. Even so, within a sustainable attack cycle, DarkHotel still maintains the potential to achieve its objectives.
Description last updated: 2024-05-04T16:25:48.391Z
What's your take? (Question 1 of 0)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
DUBNIUM is a possible alias for Darkhotel. Dubnium is a threat actor known for its execution of actions with malicious intent, primarily through the use of malware. Their operations were notably highlighted in December when they launched a campaign exploiting Adobe Flash Player. This exploit was used to distribute various samples of Dubnium'
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Darkhotel Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more