AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
Darkhotel
Aliases: DUBNIUM, Zigzag Hail
Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select guests. Darkhotel has also conducted spearphishing campaigns and infected victims through peer-to-peer and file sharing networks.
Open interactive actor investigation
ATT&CK techniques
Security Software DiscoveryT1497.002
User Activity Based ChecksT1027.013
Encrypted/Encoded FileT1573.001
Symmetric CryptographyT1080
Taint Shared ContentT1082
System Information DiscoveryT1056.001
KeyloggingT1566.001
Spearphishing AttachmentT1057
Process DiscoveryT1140
Deobfuscate/Decode Files or InformationT1189
Drive-by CompromiseT1091
Replication Through Removable MediaT1497
Virtualization/Sandbox EvasionT1497.001
System ChecksT1124
System Time DiscoveryT1553.002
Code SigningT1016
System Network Configuration DiscoveryT1083
File and Directory DiscoveryT1059.003
Windows Command ShellT1036.005
Match Legitimate Name or LocationT1105
Ingress Tool TransferT1547.001
Registry Run Keys / Startup FolderT1203
Exploitation for Client ExecutionT1204.002
Malicious FileT1547.009
Shortcut Modification
Correlated CTI and IR reports
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Vulnerability Research & Exploit Development · explicit-idModule 11 — Mobile and thick-client security
Red Team & Offensive Security · explicit-nameModule 10 — Cloud, containers, Kubernetes, and SaaS defense
Blue Team & Defensive Security · topic-matchModule 1 — Mission, authorization, and methodology
Red Team & Offensive Security · topic-matchModule 9 — AI-assisted offensive security and MCP
Red Team & Offensive Security · topic-matchDisk, file-system, and persistence forensics
Digital Forensics & Incident Response (DFIR) · topic-matchPublic code, packages, cloud artifacts, documents, and exposed secrets
OSINT & Reconnaissance · topic-matchPrompt injection, instruction hierarchy, and secure output handling
AI Security · topic-matchSecure AI development lifecycle and production release gate
AI Security · topic-matchModule 2 — The Intelligence Cycle Intelligence Types
Cyber Threat Intelligence (CTI) · topic-matchModule 8 — Operationalizing CTI (CTI → Detection)
Cyber Threat Intelligence (CTI) · topic-matchModule 2 — Asset, service, identity, and exposure context
Blue Team & Defensive Security · topic-match