Home/Threat Actor/Darkhotel
Threat Actor

Darkhotel

darkhotel · south_korea · active since 2007

Darkhotel (Karba / Luder / Tapaoux / Pioneer / Nemim / APT-C-06 / G0012) is a suspected South Korea-aligned cyber-espionage cluster active since 2007 and publicly disclosed by Kaspersky GReAT in seminal November 2014 report "The Darkhotel APT: A Story of Unusual Hospitality", named after its signature tradecraft of compromising hotel-WiFi networks at luxury East Asian hotels and selectively injecting implants into specific pre-identified high-value executive guests' software-update mechanisms (Windows Update, Adobe Flash update fakes) when those guests connected to hotel WiFi (a tradecraft pattern novel at time of 2014 disclosure and remaining relatively distinctive among publicly-tracked clusters), responsible for sustained operations against business executives, C-suite personnel, and traveling business personnel from defense, automotive, manufacturing, electronics, semiconductors, pharmaceutical, chemical, energy, financial-services, private- equity, law-firm, and consulting-firm sectors across East Asia and global business-travel routes, distinguished operationally by the signature hotel-WiFi-injection tradecraft, by sustained use of malware signed with stolen valid digital certificates from Korean and other East-Asian software developers (operational stealth exceeding peer 2010-2018 clusters), by the executive-and-business-traveler victim category (rather than broad organizational compromise), and by demonstrated 0day capability including CVE-2018-8174 VBScript engine exploitation.

analytically operationally distinct from RedHotel (China-MSS-suspected hospitality-targeting cluster, already covered as redhotel.yaml) despite naming similarity that does not reflect cluster relationship.

south_korea confidence: high 22 aliases MITRE ATT&CK G0012 ↗

Profile

Darkhotel (also tracked as Karba, Luder, Tapaoux, Pioneer, Nemim, Shadow Crane, APT-C-06, and MITRE ATT&CK G0012) is a suspected South Korea-aligned cyber-espionage cluster active since at least 2007 and publicly disclosed by Kaspersky GReAT in seminal November 10, 2014 report "The Darkhotel APT: A Story of Unusual Hospitality." The cluster name derives from its signature tradecraft: compromising hotel-WiFi networks at luxury hotels in East Asia (Japan, China, Taiwan, Hong Kong, South Korea) catering to international business travel, then selectively injecting implants into specific high-value executive guests' software- update mechanisms (notably fake Windows Update and fake Adobe Flash update injections) when those guests connected to hotel WiFi. The tradecraft was novel at time of 2014 disclosure and remains relatively distinctive among publicly-tracked clusters , sustained access to multiple compromised hotel networks across a multi-year period with selective per-target implant deployment (not random scattershot, but specific to pre-identified victims). Attribution to South Korea is grounded in victimology patterns (concentrated targeting of business executives traveling to East Asian destinations, consistent with Republic-of-Korea industrial- and-commercial-intelligence interests), language artifacts in malware code, operational hours consistent with Korean Standard Time, and stolen-certificate provenance from Korean software developers. Subsequent vendor research has generally maintained the South-Korea-aligned framing. Whether the cluster operates on behalf of South Korea's National Intelligence Service (NIS), Defense Security Support Command (DSSC, previously DSC), or another Korean government entity is not formally established; no formal state attribution has been issued by any government. The South-Korea-aligned framing should be treated as suspected based on vendor research consensus rather than formally confirmed. A small number of vendor analyses across 2017-2024 have raised alternative attribution hypotheses including possible Chinese-aligned framing based on Chinese-language operational artifacts in subsequent campaigns.

these are minority positions in the public attribution consensus but remain analytically open. Targeting focus is overwhelmingly directed at business executives, C-suite personnel, and traveling business personnel from defense, defense industrial base, automotive, manufacturing, heavy industry, electronics, semiconductors, pharmaceutical, chemical, energy, oil-and-gas, financial-services, private- equity, investment-banking, law-firm, and consulting-firm sectors. The executive-and-business-traveler victim category distinguishes Darkhotel from peer publicly-tracked clusters that typically target organizations as wholes.

Darkhotel tradecraft is anchored on specific high-value individual collection rather than broad organizational compromise. Geographic targeting spans East Asia (primary), Russia, US, Germany, Ireland, Poland, Hungary, Mongolia, and the broader global business-travel routes. A defining cluster tradecraft signature beyond the hotel-WiFi tradecraft is sustained use of malware signed with stolen valid digital certificates, particularly certificates stolen from legitimate Korean and other East-Asian software developers. The stolen-certificate approach defeats Windows code-signing- enforcement and executable-trust controls at the time of implant execution, providing operational stealth that exceeded what comparable clusters achieved during the 2010-2018 period. The stolen-certificate tradecraft has continued through 2024 per ESET, Cylance, and Trend Micro reporting. Toolkit centers on Tapaoux (the signature backdoor that gave the cluster one of its earliest vendor names), Karba (another early backdoor), InexSmar (Bitdefender 2017 disclosure of DPRK- themed-diplomatic-lure variant), Pioneer, Nemim, Asruex, and Kasidet variants. Beyond Windows the cluster has demonstrated capability across multiple architectures and operating systems. Initial-access tradecraft mixes the signature hotel-WiFi injection with conventional spear-phishing (CVE-2014-1761, CVE-2017-11882, CVE-2018-0802 Office vulnerabilities) and includes the May 2018 Kaspersky / Qihoo 360 concurrent disclosure of Darkhotel CVE-2018-8174 VBScript engine 0day exploitation, confirming continued sustained 0day-capability development across the 2014-2018 period. A handful of operational notes: First, Darkhotel is OPERATIONALLY DISTINCT from RedHotel (already covered as redhotel.yaml, China-MSS-suspected hospitality-and-government-targeting cluster disclosed by Recorded Future in August 2023) despite the naming similarity that might suggest cluster adjacency. The two clusters share a hospitality-industry-targeting element but operate different toolkits, different attribution frameworks (Darkhotel South- Korea-suspected vs RedHotel China-MSS-suspected), different victim selection patterns (Darkhotel selectively targets individual executives via compromised hotel WiFi.

RedHotel targets hospitality-industry organizations as broader victims alongside government targets), and different operational eras (Darkhotel since 2007.

RedHotel publicly disclosed 2023). The similar naming reflects vendor-naming convergence on hospitality themes rather than cluster relationship. Second, hotel-WiFi tradecraft has decreased in public Darkhotel reporting since approximately 2018, partly because hotel-WiFi security has improved (WPA3, certificate pinning in major software-update mechanisms, increased operator awareness) and partly because the cluster has diversified delivery vectors toward more conventional spear-phishing and watering-hole operations. The hotel-WiFi tradecraft remains historically consequential and continues to appear selectively but is no longer the dominant Darkhotel pattern. Third, the alternative-attribution hypothesis (possible Chinese- aligned framing) should be tracked as analytically open. The dominant vendor framing remains South-Korea-aligned but the bureau / specific-agency level attribution is not formally established. Fourth, the cluster has demonstrated sustained operational tempo and continued tradecraft evolution across nearly two decades of public-tracking. The 2007-2024 operational lifespan is unusually long among publicly-tracked APT clusters and Darkhotel represents one of the historical anchor points in the publicly-documented East-Asian cyber-espionage ecosystem.

Aliases

22
darkhoteldark hoteldark_hotelkarbaludertapaouxtapaoux apttapaoux_aptpioneernemimshadow craneshadow_craneshadowcraneapt-c-06apt_c_06aptc06higaisa overlaphot iguanahot_iguanag0012atk 52atk52

MITRE ATT&CK aliases

2
Additional names MITRE lists for G0012.
DUBNIUMZigzag Hail

Notable Campaigns

8
2018-2024Pharmaceutical and Chemical Industry Intelligence (2018-2024)
2018CVE-2018-8174 VBScript 0day Exploitation (May 2018)
2017-2024Alternative Attribution Hypothesis Questions (Ongoing)
2017InexSmar, DPRK-Themed Diplomatic Lure (Bitdefender, July 2017)
2014-2024Continued Post-Disclosure Operations (2014-2024)
2014Kaspersky GReAT: The Darkhotel APT, A Story of Unusual Hospitality (November 10, 2014)
2010-2024Stolen Valid Digital Certificate Signed Malware Tradecraft (2010-2024)
2007-2014Pre-Disclosure Hotel-WiFi Targeting Operations (2007-2014)

Attribution & Reporting

Attributed by
Kaspersky GReATTrend MicroCylance (now BlackBerry)Mandiant / FireEyeESETClearSky Cyber SecurityMicrosoftSentinelOneCisco TalosCheck Point ResearchCrowdStrike360 Threat Intelligence CenterAntiy LabsJPCERT/CCLAC Co. Ltd. (Japan)Recorded Future Insikt GroupGroup-IBCluster25
Key reporting
reportKaspersky GReAT: The Darkhotel APT, A Story of Unusual Hospitality (November 10, 2014), seminal cluster disclosure
reportKaspersky GReAT: Darkhotel's Attacks in 2015 (August 2015)
reportKaspersky GReAT: Root Cause Analysis of a Microsoft VBScript Engine 0-Day (CVE-2018-8174, May 2018)
reportTrend Micro: Darkhotel Evolution Whitepaper (December 2017)
reportESET: ESET and Darkhotel (November 2014)
reportBitdefender: InexSmar, A Sample of Darkhotel's Latest Operation (July 2017)
reportClearSky Cyber Security: Darkhotel Operations Tracking (May 2018)
reportCisco Talos: Dark Cloud, Malware Distribution via CDN (February 2018), adjacent context
reportCylance (BlackBerry): Operation Cleaver Adjacent / Darkhotel Tracking
reportRecorded Future Insikt Group: Darkhotel APT Tracking (multiple years)
reportSekoia: Darkhotel East Asia Tracking (2023-2024)
reportMalpedia Actor Profile: Darkhotel
reportMITRE ATT&CK Group G0012, Darkhotel

Operational

State sponsor

Suspected South Korea-aligned cyber-espionage cluster. Attribution to South Korea was first proposed in Kaspersky's seminal November 10, 2014 disclosure "The Darkhotel APT: A Story of Unusual Hospitality," based on victimology patterns (concentrated targeting of business executives traveling to East Asian destinations, consistent with Republic-of-Korea industrial-and-commercial- intelligence interests), language artifacts in malware code, operational hours consistent with Korean Standard Time, and stolen-certificate provenance from Korean software developers. Subsequent vendor research (Trend Micro, Cylance, FireEye / Mandiant, ESET, ClearSky) has generally maintained the South-Korea-aligned framing, though with continued analytic caution. Whether the cluster operates on behalf of South Korea's National Intelligence Service (NIS), Defense Security Support Command (DSSC, previously DSC), or another Korean government entity is not formally established. Notably, some vendor analyses have raised alternative attribution hypotheses (including possible Chinese-aligned framing based on Chinese-language operational artifacts in subsequent campaigns)

these alternative hypotheses are minority positions in the public attribution consensus but remain analytically open. No formal government attribution has been issued by any state. The South-Korea-aligned framing should be treated as suspected based on vendor research consensus rather than formally confirmed. The cluster is named "Darkhotel" after its signature tradecraft of compromising hotel-WiFi networks to deliver implants to specific business-executive guests, a tradecraft pattern that was novel at time of disclosure and remains relatively distinctive among publicly-tracked clusters.

Motivations
espionage, economic_espionage, intellectual_property_theft, industrial_intelligence, commercial_intelligence, business_executive_surveillance, geopolitical_collection
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)28/60 · 46%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)14/60 · 23%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

2 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MSHTASHELLCODE LOADERSSIGNED MALWARE WITH STOLEN CERTIFICATESSTOLEN VALID DIGITAL CERTIFICATES
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin