Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: DUBNIUM, Zigzag Hail
24
techniques
0
software
11,476
corpus matches
profile
Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select guests. Darkhotel has also conducted spearphishing campaigns and infected victims through peer-to-peer and file sharing networks.
read this carefully
11,476 corpus matches is not attribution
That count is indicators which exhibit techniques Darkhotel is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
stealth
+12 more techniques
showing 30 of 11,476
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.