All actors

Darkhotel

Also reported as Zigzag Hail, DUBNIUM, Fallout Team, APT-C-60, DarkHotel and 25 other names. Linked to South Korea by three sources.

Reports
137
Last reported
Known CVEs
160
Techniques in ATT&CK
24
Origin
South Korea
ID
G0012
Merge evidence
52 alias matches

Reports per quarter

  1. 2014 Q3: 2 reports
  2. 2014 Q4: 8 reports
  3. 2015 Q1: 2 reports
  4. 2015 Q2: no reports
  5. 2015 Q3: 3 reports
  6. 2015 Q4: 2 reports
  7. 2016 Q1: 2 reports
  8. 2016 Q2: 6 reports
  9. 2016 Q3: 3 reports
  10. 2016 Q4: no reports
  11. 2017 Q1: no reports
  12. 2017 Q2: no reports
  13. 2017 Q3: 6 reports
  14. 2017 Q4: no reports
  15. 2018 Q1: 2 reports
  16. 2018 Q2: 4 reports
  17. 2018 Q3: 4 reports
  18. 2018 Q4: 2 reports
  19. 2019 Q1: 5 reports
  20. 2019 Q2: 6 reports
  21. 2019 Q3: 2 reports
  22. 2019 Q4: 7 reports
  23. 2020 Q1: 4 reports
  24. 2020 Q2: 13 reports
  25. 2020 Q3: 9 reports
  26. 2020 Q4: 3 reports
  27. 2021 Q1: 4 reports
  28. 2021 Q2: no reports
  29. 2021 Q3: 1 report
  30. 2021 Q4: 4 reports
  31. 2022 Q1: 3 reports
  32. 2022 Q2: 3 reports
  33. 2022 Q3: no reports
  34. 2022 Q4: 1 report
  35. 2023 Q1: 2 reports
  36. 2023 Q2: 1 report
  37. 2023 Q3: no reports
  38. 2023 Q4: no reports
  39. 2024 Q1: no reports
  40. 2024 Q2: no reports
  41. 2024 Q3: 2 reports
  42. 2024 Q4: 2 reports
  43. 2025 Q1: no reports
  44. 2025 Q2: 1 report
  45. 2025 Q3: 1 report
  46. 2025 Q4: 1 report
  47. 2026 Q1: no reports
  48. 2026 Q2: 15 reports
  49. 2026 Q3: 1 report
Dated reports, 2014 Q3 to 2026 Q3.

Techniques seen in the last two years

Show all 86 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

CVEs named in reports

Show all 160 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. The Eye of the Tiger - Airbus CyberSecurity

    date ORKL added it fromORKL

  2. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

Show all 137 reports Show fewer
  1. Detecting COM Object Tasks by DarkHotel

    date in the title fromORKL

  2. Suspected DarkHotel APT activity update

    date in the title fromORKL

  3. New DarkHotel APT attack chain identified _ Zscaler

    date in the CCS '25 data Zscaler fromORKLCCS '25 data

  4. eset_jumping_the_air_gap_wp

    Malpedia library date ESET fromORKLCCS '25 data

  5. Global_APT_Research_Report_for_the_first_half_of_2021-360

    file creation date fromORKL

  6. The many personalities of Lazarus

    date in the title fromORKL

  7. XDSpy- Stealing government secrets since 2011

    date in the title fromORKL

  8. FY20 Microsoft Digital Defense Report

    Malpedia library date fromORKL

  9. Growth and Commoditization of Remote Access Trojans (X)

    date in the title fromORKL

  10. Attribution- A Puzzle

    date in the title fromORKL

  11. 0628-2020APT上半年报告-画册

    file creation date fromORKL

  12. P01_P10_eng

    file creation date fromORKL

  13. Deep-dive- The DarkHotel APT

    date in the title fromORKL

  14. Deep-dive: The DarkHotel APT

    Malpedia library date Bushido Token fromORKLCCS '25 data

  15. mpressioncss_ta_report_2019_4.pdf

    file creation date fromORKL

  16. mpressioncss_ta_report_2019_4

    date in the CCS '25 data Team T5 fromORKLCCS '25 data

  17. Lexfo-WhitePaper-The_Lazarus_Constellation

    file creation date fromORKL

  18. 2020.02.22_APT_threat_report_2019_CN_version

    Malpedia library date fromORKL

  19. Chrome 0-day exploit CVE-2019-13720 used in Operation WizardOpium

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  20. Group-IB_Hi-Tech_Crime_Trends_2019-2020_en

    file creation date fromORKL

  21. Group-IB_Hi-Tech_Crime_Trends_2019-2020

    date in the CCS '25 data Group-IB fromORKLCCS '25 data

  22. APT Trends Report Q2 2018

    file creation date Kaspersky fromORKL

  23. (cn)_higaisa_apt_report

    file creation date fromORKL

  24. Threat Group Cards: A Threat Actor Encyclopedia

    file creation date ThaiCERT fromORKL

  25. Threat Group Cards: A Threat Actor Encyclopedia

    file creation date Martijn van der Heide fromORKL

  26. ScarCruft continues to evolve, introduces Bluetooth harvester _ Securelist

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  27. mpressioncss_ta_report_2019.pdf

    Malpedia library date fromORKL

  28. Report2019GlobalThreatReport

    file creation date fromORKL

  29. CrowdStrike_GTR_2019.pdf

    file creation date fromORKL

  30. 2019.01.03.Tencent_APT_Summary_report_2018_CN_Version

    file creation date fromORKL

  31. 2018 APT Summary Report CN version

    file creation date fromORKL

  32. HITB-SG-2018-E - In the trails of WINDSHIFT [Autosaved]

    date in the CCS '25 data Bellingcat fromORKLCCS '25 data

  33. APT Trends Report Q2 2018

    date in the title fromORKL

  34. A Study of RATs- Third Timeline Iteration

    date in the title fromORKL

  35. ukatemicrysys_territorialdispute

    Malpedia library date fromORKL

  36. 'DarkHotel' APT Uses New Methods to Target Politicians

    date in the title fromORKL

  37. Inexsmar: An unusual DarkHotel campaig

    date in the CCS '25 data Bitdefender fromORKLCCS '25 data

  38. blog Inexsmar

    date in the CCS '25 data Bitdefender fromORKLCCS '25 data

  39. Bartholomew-GuerreroSaade-VB2016.indd

    Malpedia library date Kaspersky fromORKL

  40. 摩诃草组织

    file creation date fromORKL

  41. Asruex: Malware Infecting through Shortcut Files

    date in the CCS '25 data JPCERT fromORKLCCS '25 data

  42. Reverse-engineering DUBNIUM's Flash-targeting exploit

    date in the CCS '25 data Microsoft fromORKLCCS '25 data

  43. Reverse-engineering DUBNIUM

    date in the title fromORKL

  44. Reverse-engineering DUBNIUM

    date in the CCS '25 data Microsoft fromORKLCCS '25 data

  45. JAKU

    file creation date fromORKL

  46. 2015年中国高持续性威胁(APT)研究报告

    file creation date fromORKL

  47. Darkhotel's attacks in 2015

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  48. Darkhotel’s attacks in 2015

    date in the title fromORKL

  49. Who’s Really Spreading through the Bright Star-

    date in the title fromORKL

  50. The Darkhotel APT

    date in the title fromORKL

  51. Darkhotel Indicators Of Compromise

    file creation date Kaspersky fromORKL

  52. darkhotelappendixindicators_kl_1.1

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  53. The Darkhotel Apt A Story Of Unusual Hospitality v1.0

    file creation date Kaspersky fromORKL

  54. The Darkhotel APT A Story of Unusual Hospitality v1.1

    date in the CCS '25 data Kaspersky fromCCS '25 data

  55. The Eye of the Tiger - Airbus D&S CyberSecurity blog

    date in the CCS '25 data Symantec fromORKLCCS '25 data

  56. The Eye Of The Tiger (Pitty Tiger)

    Malpedia library date Airbus fromORKL

Newest first. Details opens the report in Explore.