DarkHotel

THREAT ACTOR PROFILE

DarkHotel

DarkHotel

DarkHotel

DUBNIUM

DarkHotel is an East Asia-linked espionage group active since at least 2010, long associated with targeting high-profile individuals through hotel networks. It has since broadened to foreign trade, government, research, defense and electronics sectors across China, North Korea, Japan, Myanmar and Russia, and its recent campaigns use bring-your-own-vulnerable-driver (BYOVD) techniques and custom RPC-based tooling.

East Asia-linked

Government / Executives / Defense

First seen

2010

Latest IOC

-

IP indicators

Hosts

SHA256 hashes

Posts

NAMES AND ALIASES

DarkHotel, DUBNIUM and APT-C-06

DarkHotel is tracked under a long list of vendor names. It maps to one entry among the East Asian espionage actors we track, and its regional espionage focus overlaps with crews like Kimsuky.

-

-

-

GROUP PROFILE

Targeted surveillance of high-value individuals

DarkHotel runs precise espionage against carefully chosen targets. Its classic approach compromised hotel Wi-Fi to reach travelling executives, and it has consistently favored selective, high-value targeting over broad campaigns.

Our record ties it to espionage against executives, government, defense and electronics targets across East Asia and beyond. A February 2025 campaign targeted individuals involved in trade with North Korea using a malicious certificate-installation package.

The group's tradecraft includes spearphishing, malicious installers, BYOVD to disable defenses, and custom RPC-based components, alongside stealers such as ObserverStealer.

Facts:

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Victims reported in our records and posts:

-

-

-

-

-

-

ATTACK LIFECYCLE

Phishing and BYOVD into custom malware

The stages below come from DarkHotel and APT-C-06 activity in posts we track on our IOC Hunter feed.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

MALWARE AND TOOLING

DarkHotel implants and ObserverStealer

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

CVES EXPLOITED

Targeted delivery without a fixed CVE set

DarkHotel is historically known for using zero-day exploits, but the campaigns in our records rely on spearphishing, malicious installers and BYOVD techniques rather than a confirmed, currently tracked set of exploited CVEs. Detection should focus on the malicious certificate-installer lure, the BYOVD behavior and the group's custom implants.

DarkHotel

IOCS FROM HUNT.IO PLATFORM

Latest IOCs

We currently track - IP indicators, - hosts, and - SHA256 hashes for Akira across - intelligence posts, with the most recent indicator dated -. The sample below is limited to indicators from the latest posts. It is not the full set.

DarkHotel

Hosting Company

IPs

Date

Hosting Company

IPs

Date

144.126.202.227

LameHug exfil

06-17

Showing a sample of recent indicators

Get the complete

DarkHotel

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

DarkHotel

IOC set, full IP, host and hash history.

NOTABLE CAMPAIGNS

BYOVD attacks and new RPC tooling

Reporting tracks the group's recent tradecraft.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

Showing a sample of recent indicators

Get the complete

DarkHotel

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

DarkHotel

IOC set, full IP, host and hash history.