Threat actor · all actors
DarkhotelG0012 state
🇰🇷 KR
aka Darkhotel, DUBNIUM, Zigzag Hail, Fallout Team, Karba, Luder, Nemim, Nemin, Tapaoux, Pioneer, Shadow Crane, APT-C-06, SIG25, TUNGSTEN BRIDGE, T-APT-02, G0012, ATK52
Last updated: 2026-08-20
About this actor
[Darkhotel](https://attack.mitre.org/groups/G0012) is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select guests. [Darkhotel](https://attack.mitre.org/groups/G0012) has also conducted spearphishing campaigns and infected victims through peer-to-peer and file sharing networks.(Citation: Kaspersky Darkhotel)(Citation: Securelist Darkhotel Aug 2015)(Citation: Microsoft Digital Defense FY20 Sept 2020)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
CrowdStrikenation-animal names
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 34 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1016System Network Configuration Discovery ↗T1027Obfuscated Files or Information ↗T1027.013Encrypted/Encoded File ↗T1036Masquerading ↗T1036.005Match Legitimate Resource Name or Location ↗T1056Input Capture ↗T1056.001Keylogging ↗T1057Process Discovery ↗T1059Command and Scripting Interpreter ↗T1059.003Windows Command Shell ↗T1080Taint Shared Content ↗T1082System Information Discovery ↗T1083File and Directory Discovery ↗T1091Replication Through Removable Media ↗T1105Ingress Tool Transfer ↗T1124System Time Discovery ↗T1140Deobfuscate/Decode Files or Information ↗T1189Drive-by Compromise ↗T1203Exploitation for Client Execution ↗T1204User Execution ↗T1204.002Malicious File ↗T1497Virtualization/Sandbox Evasion ↗T1497.001System Checks ↗T1497.002User Activity Based Checks ↗T1518Software Discovery ↗T1518.001Security Software Discovery ↗T1547Boot or Logon Autostart Execution ↗T1547.001Registry Run Keys / Startup Folder ↗T1553Subvert Trust Controls ↗T1553.002Code Signing ↗T1566Phishing ↗T1566.001Spearphishing Attachment ↗T1573Encrypted Channel ↗T1573.001Symmetric Cryptography ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-3 | 17 / 34 | 50% |
SI-4 | 17 / 34 | 50% |
CM-2 | 16 / 34 | 47% |
CM-6 | 15 / 34 | 44% |
CA-7 | 13 / 34 | 38% |
CM-7 | 11 / 34 | 32% |
SI-7 | 11 / 34 | 32% |
SC-7 | 10 / 34 | 29% |
AC-4 | 9 / 34 | 26% |
AC-3 | 8 / 34 | 24% |
AC-6 | 8 / 34 | 24% |
SI-10 | 8 / 34 | 24% |
SI-2 | 8 / 34 | 24% |
IA-9 | 6 / 34 | 18% |
AC-2 | 5 / 34 | 15% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- Frankenstein 0.38
- Sidewinder 0.36
- Windshift 0.35
- Tropic Trooper 0.34
- Higaisa 0.34
Same nation-state
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00