THREAT_ACTOR · G0012
Darkhotel
Also known as: Darkhotel, DUBNIUM, Zigzag Hail
Profile
Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select guests. Darkhotel has also conducted spearphishing campaigns and infected victims through peer-to-peer and file sharing networks.
MITRE ATT&CK ↗Techniques
24 ATT&CK techniques attributed to this actor.
T1016 System Network Configuration DiscoveryT1027.013 Encrypted/Encoded FileT1036.005 Match Legitimate Resource Name or LocationT1056.001 KeyloggingT1057 Process DiscoveryT1059.003 Windows Command ShellT1080 Taint Shared ContentT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1091 Replication Through Removable MediaT1105 Ingress Tool TransferT1124 System Time DiscoveryT1140 Deobfuscate/Decode Files or InformationT1189 Drive-by CompromiseT1203 Exploitation for Client ExecutionT1204.002 Malicious FileT1497 Virtualization/Sandbox EvasionT1497.001 System ChecksT1497.002 User Activity Based ChecksT1518.001 Security Software DiscoveryT1547.001 Registry Run Keys / Startup FolderT1553.002 Code SigningT1566.001 Spearphishing AttachmentT1573.001 Symmetric Cryptography
Related corpus activity
10,154 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Darkhotel.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2026-0740 | cve | — | 85 | 1 |
Showing the top 30 by severity of 10,154.