{
	"id": "f2512e3a-0720-4800-9ae3-ead4b4345e61",
	"created_at": "2026-04-06T00:19:33.585507Z",
	"updated_at": "2026-04-10T03:29:57.892116Z",
	"deleted_at": null,
	"sha1_hash": "85f2fdaa2e6b4cbbe1de1dd0edd56988abe8c8f5",
	"title": "DarkHotel (Malware Family)",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 38005,
	"plain_text": "DarkHotel (Malware Family)\r\nBy Fraunhofer FKIE\r\nArchived: 2026-04-05 22:23:35 UTC\r\nwin.dubnium_darkhotel (Back to overview)\r\nDarkHotel\r\nActor(s): DarkHotel\r\nThere is no description at this point.\r\nReferences\r\n2020-03-23 ⋅ Reuters ⋅ Christopher Bing, Jack Stubbs, Raphael Satter\r\nExclusive: Elite hackers target WHO as coronavirus cyberattacks spike\r\nDarkHotel\r\n2016-06-30 ⋅ JPCERT/CC ⋅ Shusei Tomonaga\r\nAsruex: Malware Infecting through Shortcut Files\r\nDarkHotel\r\n2016-06-09 ⋅ Microsoft ⋅ Jeong Wook Oh\r\nReverse-engineering DUBNIUM\r\nDarkHotel\r\n2015-08-10 ⋅ Kaspersky Labs ⋅ GReAT\r\nDarkhotel’s attacks in 2015\r\nDarkHotel DarkHotel\r\nThere is no Yara-Signature yet.\r\nSource: https://malpedia.caad.fkie.fraunhofer.de/details/win.dubnium_darkhotel\r\nhttps://malpedia.caad.fkie.fraunhofer.de/details/win.dubnium_darkhotel\r\nPage 1 of 1",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"references": [
		"https://malpedia.caad.fkie.fraunhofer.de/details/win.dubnium_darkhotel"
	],
	"report_names": [
		"win.dubnium_darkhotel"
	],
	"threat_actors": [
		{
			"id": "1dadf04e-d725-426f-9f6c-08c5be7da159",
			"created_at": "2022-10-25T15:50:23.624538Z",
			"updated_at": "2026-04-10T02:00:05.286895Z",
			"deleted_at": null,
			"main_name": "Darkhotel",
			"aliases": [
				"Darkhotel",
				"DUBNIUM",
				"Zigzag Hail"
			],
			"source_name": "MITRE:Darkhotel",
			"tools": null,
			"source_id": "MITRE",
			"reports": null
		},
		{
			"id": "b13c19d6-247d-47ba-86ba-15a94accc179",
			"created_at": "2024-05-01T02:03:08.149923Z",
			"updated_at": "2026-04-10T02:00:03.763147Z",
			"deleted_at": null,
			"main_name": "TUNGSTEN BRIDGE",
			"aliases": [
				"APT-C-06 ",
				"ATK52 ",
				"CTG-1948 ",
				"DUBNIUM ",
				"DarkHotel ",
				"Fallout Team ",
				"Shadow Crane ",
				"Zigzag Hail "
			],
			"source_name": "Secureworks:TUNGSTEN BRIDGE",
			"tools": [
				"Nemim",
				"Tapaoux"
			],
			"source_id": "Secureworks",
			"reports": null
		},
		{
			"id": "2b4eec94-7672-4bee-acb2-b857d0d26d12",
			"created_at": "2023-01-06T13:46:38.272109Z",
			"updated_at": "2026-04-10T02:00:02.906089Z",
			"deleted_at": null,
			"main_name": "DarkHotel",
			"aliases": [
				"T-APT-02",
				"Nemim",
				"Nemin",
				"Shadow Crane",
				"G0012",
				"DUBNIUM",
				"Karba",
				"APT-C-06",
				"SIG25",
				"TUNGSTEN BRIDGE",
				"Zigzag Hail",
				"Fallout Team",
				"Luder",
				"Tapaoux",
				"ATK52"
			],
			"source_name": "MISPGALAXY:DarkHotel",
			"tools": [],
			"source_id": "MISPGALAXY",
			"reports": null
		},
		{
			"id": "c0cedde3-5a9b-430f-9b77-e6568307205e",
			"created_at": "2022-10-25T16:07:23.528994Z",
			"updated_at": "2026-04-10T02:00:04.642473Z",
			"deleted_at": null,
			"main_name": "DarkHotel",
			"aliases": [
				"APT-C-06",
				"ATK 52",
				"CTG-1948",
				"Dubnium",
				"Fallout Team",
				"G0012",
				"G0126",
				"Higaisa",
				"Luder",
				"Operation DarkHotel",
				"Operation Daybreak",
				"Operation Inexsmar",
				"Operation PowerFall",
				"Operation The Gh0st Remains the Same",
				"Purple Pygmy",
				"SIG25",
				"Shadow Crane",
				"T-APT-02",
				"TieOnJoe",
				"Tungsten Bridge",
				"Zigzag Hail"
			],
			"source_name": "ETDA:DarkHotel",
			"tools": [
				"Asruex",
				"DarkHotel",
				"DmaUp3.exe",
				"GreezeBackdoor",
				"Karba",
				"Nemain",
				"Nemim",
				"Ramsay",
				"Retro",
				"Tapaoux",
				"Trojan.Win32.Karba.e",
				"Virus.Win32.Pioneer.dx",
				"igfxext.exe",
				"msieckc.exe"
			],
			"source_id": "ETDA",
			"reports": null
		}
	],
	"ts_created_at": 1775434773,
	"ts_updated_at": 1775791797,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/85f2fdaa2e6b4cbbe1de1dd0edd56988abe8c8f5.pdf",
		"text": "https://archive.orkl.eu/85f2fdaa2e6b4cbbe1de1dd0edd56988abe8c8f5.txt",
		"img": "https://archive.orkl.eu/85f2fdaa2e6b4cbbe1de1dd0edd56988abe8c8f5.jpg"
	}
}