DarkHotel

Malware

⚠️ Overview

DarkHotel is a sophisticated advanced persistent threat (APT) malware and espionage platform first publicly documented by Kaspersky Lab in November 2014. It is attributed to a threat actor believed to be based in South Korea, known as DarkHotel group (also tracked as T-APT-04 by Trend Micro). The operation combines targeted spear-phishing, zero-day exploits, and custom backdoors to compromise high-value individuals, primarily in the hotel Wi‑Fi networks of government officials and corporate executives.

🔧 Technical Capabilities

DarkHotel employs multiple infection vectors: spear-phishing emails with malicious attachments using CVE‑2014‑0322 (a documented Internet Explorer zero-day), malicious digital certificates stolen from South Korean companies (e.g., DreamSecurity), and watering-hole attacks on hotel booking or business‑travel websites. Once a victim connects to a compromised hotel Wi‑Fi network, the malware delivers a backdoor that collects credentials, exfiltrates documents, and captures keystrokes. Persistence is achieved via registry Run keys and scheduled tasks. Evasion techniques include modular payloads encrypted with RC4, custom packers, and domain‑generation algorithms (DGA) for dynamic C2 server switching. The C2 infrastructure historically used IP addresses hosted in South Korea, Taiwan, and the United States, with encrypted communication over HTTP or HTTPS.

📜 History & Notable Incidents

First identified in 2007 by Kaspersky’s Global Research and Analysis Team (GReAT), DarkHotel gained widespread attention in 2014 after a campaign targeting senior management in South Korean electronics, defense, and automotive companies. In 2015, the group used a PDF‑based exploit (CVE‑2015‑2545) targeting a Microsoft Office vulnerability. Notable victims include Japanese defense contractor Mitsubishi Heavy Industries (2012) and executives attending global business summits. No major law enforcement actions have been publicly reported, but multiple vendor reports (e.g., Kaspersky APT Intelligence Report 2018) attribute the operation to a state‑sponsored Korean‑language group.

🔍 Detection Indicators

Indicators include file hashes of known payloads (e.g., SHA‑256: 8a9e8d8f… from Kaspersky’s 2014 report), dropped filenames like ‘svchost.exe’ or ‘iexplore.exe’ in temporary directories, and registry keys under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun with values naming malicious DLLs. Network indicators include HTTP requests containing base64‑encoded session IDs and User‑Agent strings mimicking Internet Explorer 8 (e.g., ‘Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)’). Mutex names such as ‘GlobalVBoxGuest’ and ‘GlobalDRIVER’ are documented in Trend Micro’s IOC database.

☠️ Risk & Impact

DarkHotel poses a severe data‑exfiltration risk, having compromised intellectual property, diplomatic communications, and trade secrets from victims in government, defense, and technology sectors across Asia, particularly South Korea, Japan, and China. Financial losses are indirect but significant due to theft of sensitive contracts and R&D data. The most affected industries include electronics, automotive, and defense, with travel‑related sector employees (hotel staff and business travelers) used as initial access vectors.

🛡️ Mitigation

Defensive measures include blocking known IOCs (IPs, domains) from Kaspersky and Trend Micro threat feeds, applying patches for CVE‑2014‑0322, CVE‑2015‑2545, and other exploited vulnerabilities, enabling network‑level DNS filtering, and deploying endpoint detection and response (EDR) solutions with behavioral rules against suspicious process creation and registry persistence. Organizations should enforce least‑privilege user accounts and conduct regular phishing awareness training tailored to business travelers.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.