{
  "family": "darkhotel",
  "sample_count": 1,
  "category": "backdoor",
  "description": "<h3>Executive Summary</h3>\nDarkhotel is a highly sophisticated Advanced Persistent Threat (APT) group and associated malware toolset, historically active since at least 2007. Believed to be a state-sponsored espionage group operating out of the Korean peninsula, Darkhotel is infamous for its surgical, highly targeted operations against corporate executives, government officials, and defense contractors. Their signature tactic involves compromising luxury hotel Wi-Fi networks to distribute bespoke spyware to high-value targets while they travel.\n\n<h3>Infection Vector and Technical Capabilities</h3>\nDarkhotel's primary vector is exceptionally targeted. The group breaches the internal networks of luxury hotels (often via compromised server management software). When a specific, pre-identified target checks in and connects to the hotel Wi-Fi, the attackers intercept the connection and serve a forged software update prompt (e.g., a fake Adobe Flash or Google Toolbar update) that is digitally signed using stolen certificates.\n\nOnce the victim executes the \"update,\" the Darkhotel toolset deploys:\n<ul>\n<li><strong>Digital Signature Abuse:</strong> The malware is almost always signed with legitimate, though stolen, digital certificates to bypass strict application whitelisting and EDR solutions that trust signed binaries.</li>\n<li><strong>Targeted Espionage:</strong> The core payload is a sophisticated information stealer and keylogger. It is designed to harvest cached passwords in major browsers, steal SSH keys, intercept VoIP communications, and silently exfiltrate sensitive intellectual property.</li>\n<li><strong>Selective Execution:</strong> The malware often checks the system language and specific environmental variables; if the target does not match the precise profile the attackers are seeking, the malware may safely delete itself to avoid detection by security researchers.</li>\n</ul>\n\n<h3>Threat Assessment</h3>\nThe detection of Darkhotel malware is a critical, enterprise-level incident. It indicates that the organization is being actively targeted by a highly resourced, patient, and capable nation-state adversary seeking to steal high-value intellectual property or strategic intelligence.\n\n<h3>Incident Response and Remediation</h3>\n<ul>\n<li><strong>Full APT IR Protocol:</strong> Standard remediation is insufficient. The presence of Darkhotel requires the activation of a specialized Incident Response team to conduct a comprehensive network hunt, assuming the attackers have established multiple layers of persistence (including backdoored firmware).</li>\n<li><strong>Forensic Capture:</strong> Do not immediately wipe the machine. Capture full volatile memory (RAM) and disk images to reverse engineer the specific, bespoke payload deployed against the target to understand what data was targeted.</li>\n<li><strong>Travel Security Policy Revision:</strong> The hallmark of this attack vector requires a fundamental shift in corporate travel security. Executives traveling to high-risk regions must utilize dedicated \"burner\" laptops with strict VPN tunneling policies and must never accept software updates over public or hotel Wi-Fi networks.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "APT.Darkhotel",
    "Trojan.Darkhotel",
    "Tapaoux"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1189",
    "T1116",
    "T1056",
    "T1555"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-01T17:20:25Z",
  "type": "APT / Espionage Trojan",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}