DarkHotel is a long-running espionage threat actor active since at least the late 2000s and widely assessed to be linked to the Korean Peninsula. The group is best known for highly selective targeting of business executives, government officials, diplomats, defense-related personnel, and other high-value individuals, including through compromises of luxury hotel networks used to deliver malware to traveling targets. Over time, its targeting has expanded beyond hotel guests to include government agencies, research institutions, military and defense sectors, foreign trade organizations, and entities in Japan, China, India, Myanmar, North Korea, and parts of Europe. Commonly reported aliases include APT-C-60, Dubnium, Tapaoux, Shadow Crane, Paladin, Purple Pygmy, Fallout Team, Nemim, Templar, Tieonjoe, Zigzag Hail, and related naming variants such as Dark Hotel and Dark_Hotel. Some reporting also links DarkHotel with activity clusters tracked as APT-C-60, particularly campaigns targeting organizations in Japan and deploying the SpyGlace backdoor. DarkHotel is associated with spear-phishing, malicious archives, shortcut-file execution chains, DLL side-loading, staged downloaders, abuse of legitimate cloud and developer services, and selective use of signed or trusted binaries to blend into normal activity. Recent operations attributed to APT-C-60 have used phishing emails to deliver archives containing malicious LNK files that invoke mshta.exe, execute embedded or downloaded scripts, abuse legitimate git.exe execution, and retrieve later-stage payloads from mainstream developer platforms and content delivery services before installing SpyGlace. The actor has also been observed using living-off-the-land techniques and ordinary Windows components to reduce detection opportunities. The group’s malware and tooling show a strong emphasis on modularity, stealth, and anti-analysis. Reported behaviors include discovery of running security products and anti-malware processes, collection of host and operating system details, collection of network adapter and IP information, process enumeration, file discovery, string and import decryption including RC4 use, and persistence through Registry Run keys. Other reporting describes more advanced frameworks using Microsoft-signed binaries for DLL side-loading, encrypted module loading, multi-stage process injection, local RPC for component separation, and distinct surveillance modules for capabilities such as keylogging, screen capture, and USB data theft. DarkHotel has historically been associated with forged or stolen code-signing certificates, kernel-mode keylogging, zero-day exploitation in some operations, and disciplined operational security, including selective victiming and temporary staging of malware infrastructure around target activity windows. Its tradecraft is consistent with a mature espionage actor focused on credential theft, surveillance, and long-term access to strategically valuable targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
45 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
9 CVEs this actor has used in observed campaigns. 9 of them exploited in the wild.
Darkhotel has exploited Adobe Flash vulnerability CVE-2015-8651 for execution.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
May 2018: a new wave of targeted attacks abusing CVE-2018-8174 (this exploit has been associated with the DarkHotel APT group, as described on Securelist), with diplomatic, defense, manufacturing, military and government targets in Asia and Eastern Europe;
Google TAG Team discovered CVE-2019–1367 exploited in the wild by a threat actor... CVE-2019–1367 enables Remote Code Execution (RCE) in the context of Internet Explorer in all version from 8, 9, 10 and 11 due to a memory corruption in jscript.dll... Microsoft released a patch and encouraged users to disable jscript.dll.
Quihoo 360 published details about DarkHotel APT switching to another 0-day exploit... CVE-2020–0674... Based on Google P0 tweet below, it seems that CVE-2020–0674 is patching a misfix of the earlier CVE-2019–1367... 15th May 2020 : First write up of CVE-2020–0674 by F-secure labs.
4 more CVEs tied to this actor tracked in Mallory.
249 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting spear-phishing campaigns against organizations in Japan to deploy the SpyGlace backdoor, using LNK loaders, Proton Drive links, public CDNs, and legitimate developer platforms while blending in with living-off-the-land techniques.
Conducting spear-phishing campaigns against organizations in Japan to deliver SpyGlace via booby-trapped RAR/LNK files, abusing trusted developer and cloud services such as Proton Drive, GitHub, GitLab, jsDelivr, and Codeberg to evade detection.
Conducting spear-phishing-led intrusion campaigns against organizations in Japan, using Proton Drive-delivered RAR/LNK payload chains, mshta.exe-executed embedded JavaScript, git.exe for script execution, and legitimate developer/CDN services to stage and deliver SpyGlace malware.
Conducting spear-phishing-led intrusions against organizations in Japan in 2026, using Proton Drive-delivered RAR archives containing LNK files, JavaScript execution via mshta.exe, git.exe-assisted script execution, abuse of legitimate services including GitHub, GitLab, jsDelivr, and Codeberg for staging/downloading payloads, and ultimately deploying SpyGlace malware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.