South KoreaWidely attributedUnknownMITRE G0012

Darkhotel

Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select guests. Darkhotel has also conducted spearphishing campaigns and infected victims through peer-to-peer and file sharing networks.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
0.0
None signal strength
Mentions0
Sources0
High conf.0
First observed
2017-05-31
Last active
Origin
South Korea
Aliases
4
Techniques
24
Campaigns
0
South Korea

Attribution signals

No attribution signals extracted yet — signals populate automatically as articles are processed.