A suspected DarkHotel campaign targeted luxury hotels in Macao with spear-phishing emails carrying malicious Excel attachments disguised as inquiries from the Macao Government Tourism Office. Researchers said the operation hit management personnel at at least 17 hotels, including Grand Coloane Resort and Wynn Palace, and used macros, VBS, and PowerShell to collect system information and exfiltrate data to the command-and-control domain fsm-gov.com. The activity was assessed with only moderate confidence as DarkHotel-linked because infrastructure tied to the campaign had also appeared in unrelated criminal phishing activity.
The intrusion relied on Windows Scheduled Tasks to maintain persistence and repeatedly execute payloads, including tasks created through a COM object rather than only via schtasks.exe, a method that can evade detections focused on command-line task creation. Hunting guidance highlighted suspicious Office behavior such as Excel loading taskschd.dll and wshom.ocx, short-lived tasks running every five minutes, and task names like MicrosoftOneDriveMgmt and MicrosoftOneDriveSync. Defenders were advised to monitor scheduled task creation logs, image-load telemetry, and task executions from user-writable paths, and to use Microsoft Defender for Endpoint Attack Surface Reduction rules to block or audit Office applications creating executable content.

Get the infrastructure and lures behind it.
6 events from the most recent confirmed update back to the earliest known activity.
A March 2022 blog post documented detection and hunting guidance for scheduled tasks created through the Task Scheduler COM object rather than schtasks.exe. The post tied the technique to activity moderately attributed to DarkHotel and recommended telemetry from Defender for Endpoint, Sysmon, and Windows task creation logs.
The campaign appears to have slowed or stopped after January 18, 2022. Researchers suggested COVID-19 disruptions and the cancellation or postponement of relevant events in Macao may have reduced the operation's value to the attackers.
Red Canary published a threat report in 2022 describing how adversaries abuse Windows Scheduled Tasks for persistence and execution. The report highlighted common attacker patterns including schtasks.exe usage, SYSTEM-level tasks, and Qbot-linked regsvr32 execution.
On December 7, 2021, attackers sent an email to 17 hotels in the Macao area posing as the Macao Government Tourism Office. The message carried a malicious Excel attachment named “信息.xls” and was part of the suspected DarkHotel campaign.
In December 2021, the Macao Security Force Bureau became aware of the campaign and publicly warned about the suspicious domain used in it. The warning related to infrastructure tied to the phishing operation targeting local hotels.
A spear-phishing campaign targeting luxury hotels in Macao, China began in the latter half of November 2021. The operation focused on hotel management personnel and used malicious Excel attachments to gain access to hotel networks and booking systems.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
docs.microsoft.com
Open sourcetrellix.com
Open sourcecyberandramen.net
Open sourceredcanary.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.