• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EST 14:12
CET 20:12
KST 04:12
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
RSL Season 3 - Playoffs Preview0RSL Season 3 - RO16 Groups C & D Preview0RSL Season 3 - RO16 Groups A & B Preview2TL.net Map Contest #21: Winners12Intel X Team Liquid Seoul event: Showmatches and Meet the Pros10
Community News
Weekly Cups (Nov 24-30): MaxPax, Clem, herO win2BGE Stara Zagora 2026 announced14[BSL21] Ro.16 Group Stage (C->B->A->D)4Weekly Cups (Nov 17-23): Solar, MaxPax, Clem win3RSL Season 3: RO16 results & RO8 bracket13
StarCraft 2
General
Weekly Cups (Nov 24-30): MaxPax, Clem, herO win SC2 Proleague Discontinued; SKT, KT, SGK, CJ disband BGE Stara Zagora 2026 announced Information Request Regarding Chinese Ladder SC: Evo Complete - Ranked Ladder OPEN ALPHA
Tourneys
$5,000+ WardiTV 2025 Championship Constellation Cup - Main Event - Stellar Fest RSL Revival: Season 3 Tenacious Turtle Tussle [Alpha Pro Series] Nice vs Cure
Strategy
Custom Maps
Map Editor closed ?
External Content
Mutation # 502 Negative Reinforcement Mutation # 501 Price of Progress Mutation # 500 Fright night Mutation # 499 Chilling Adaptation
Brood War
General
[ASL20] Ask the mapmakers — Drop your questions Which season is the best in ASL? FlaSh's Valkyrie Copium BGH Auto Balance -> http://bghmmr.eu/ BW General Discussion
Tourneys
[Megathread] Daily Proleagues [BSL21] RO16 Group B - Sunday 21:00 CET [BSL21] RO16 Group C - Saturday 21:00 CET Small VOD Thread 2.0
Strategy
Game Theory for Starcraft How to stay on top of macro? Current Meta PvZ map balance
Other Games
General Games
Stormgate/Frost Giant Megathread The Perfect Game Path of Exile Nintendo Switch Thread Should offensive tower rushing be viable in RTS games?
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
Mafia Game Mode Feedback/Ideas TL Mafia Community Thread
Community
General
US Politics Mega-thread Things Aren’t Peaceful in Palestine Russo-Ukrainian War Thread The Big Programming Thread Artificial Intelligence Thread
Fan Clubs
White-Ra Fan Club
Media & Entertainment
[Manga] One Piece Movie Discussion! Anime Discussion Thread
Sports
2024 - 2026 Football Thread Formula 1 Discussion NBA General Discussion MLB/Baseball 2023
World Cup 2022
Tech Support
Computer Build, Upgrade & Buying Resource Thread
TL Community
Where to ask questions and add stream? The Automated Ban List
Blogs
James Bond movies ranking - pa…
Topin
Esports Earnings: Bigger Pri…
TrAiDoS
Thanks for the RSL
Hildegard
Saturation point
Uldridge
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1293 users

The Darkhotel APT

Blogs > Blazinghand
Post a Reply
Blazinghand *
Profile Blog Joined December 2010
United States25555 Posts
December 06 2014 11:33 GMT
#1
The Darkhotel APT





Kastersky has identified hacking activities that target powerful executives and business personnel around the world by infecting hotel networks. Some exerpts:

Moreover, this crew's most unusual characteristic is that for several years the Darkhotel APT has maintained a capability to use hotel networks to follow and hit selected targets as they travel around the world. These travelers are often top executives from a variety of industries doing business and outsourcing in the APAC region. Targets have included CEOs, senior vice presidents, sales and marketing directors and top R&D staff. This hotel network intrusion set provides the attackers with precise global scale access to high value targets.

[...]

Victim categories include the following verticals:
  • Very large electronics manufacturing
  • Investment capital and private equity
  • Pharmaceuticals
  • Cosmetics and chemicals manufacturing offshoring and sales
  • Automotive manufacturer offshoring services
  • Automotive assembly, distribution, sales, and services
  • Defense industrial base
  • Law enforcement and military services
  • Non-governmental organizations


[...]

When Kaspersky Lab researchers visited Darkhotel incident destinations with honeypot machines they did not attract Darkhotel attacks, which suggests the APT acts selectively.. Further work demonstrated just how careful these attackers were to hide their activity - as soon as a target was effectively infected, they deleted their tools from the hotel network staging point, maintaining a hidden status.


Read the rest of the article: https://securelist.com/blog/research/66779/the-darkhotel-apt/

Or the paper itself: https://securelist.com/files/2014/11/darkhotel_kl_07.11.pdf

It's interesting to read about just how vulnerable we really are to this sort of thing. How often do we click through the warnings when we connect to a public or unsecured network? Although at least one step involves tricking people into installing software, it looks like they may have used some particularly good ruses (tricking certificate authorities, or using 0-day vulnerabilities in Adobe Flash updater) to get their software onto the computers.

I'm pretty careful to use 2-step verification for email, not install random internet shit, and run virus scans fairly regularly. I wonder if there's more I should be doing to make sure I don't get hoodwinked, though. I'm not a high value target (it looks like this group selectively targeted business execs) so I don't have to worry much. What about you? what do you do to keep your computer secure?

***
When you stare into the iCCup, the iCCup stares back.
TL+ Member
Stratos
Profile Blog Joined July 2010
Czech Republic6104 Posts
December 06 2014 12:32 GMT
#2
On December 06 2014 20:33 Blazinghand wrote:
What about you? what do you do to keep your computer secure?

Nothing. I live in constant fear someone may find out I still watch Xena on a daily basis.
En Taro Violet
Deleuze
Profile Blog Joined December 2010
United Kingdom2102 Posts
December 06 2014 13:40 GMT
#3
I like the way that the video misrepresents the hacker as a tattooed punk whereas the reality is that they are just the same as the execs upon whom they prey.
“An image of thought called philosophy has been formed historically and it effectively stops people from thinking.” ― Gilles Deleuze, Dialogues II
Blazinghand *
Profile Blog Joined December 2010
United States25555 Posts
December 06 2014 14:31 GMT
#4
On December 06 2014 22:40 Deleuze wrote:
I like the way that the video misrepresents the hacker as a tattooed punk whereas the reality is that they are just the same as the execs upon whom they prey.

the goggles are the best part
When you stare into the iCCup, the iCCup stares back.
TL+ Member
Gamegene
Profile Blog Joined June 2011
United States8308 Posts
December 06 2014 23:26 GMT
#5
(Completely uninformed about subject)

Is this malware being exclusively use for one party's benefit or is it being used as a tool by several different parties targeting the same interest groups in different countries?

The loot sounds like the stuff various governments (China?) would love to get their fingers on.
Throw on your favorite jacket and you're good to roll. Stroll through the trees and let your miseries go.
Please log in or register to reply.
Live Events Refresh
StarCraft2.fi
17:00
15V Cup / Groups Day 2
starcraft2fi 99
Liquipedia
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
mouzHeroMarine 528
Livibee 138
BRAT_OK 67
JuggernautJason42
MindelVK 41
Railgan 18
StarCraft: Brood War
Calm 4009
Larva 773
Rush 355
firebathero 178
Dewaltoss 63
soO 40
Movie 9
HiyA 9
Dota 2
qojqva4794
Dendi1136
420jenkins419
Counter-Strike
fl0m8455
pashabiceps1374
zeus1121
Heroes of the Storm
Liquid`Hasu181
Other Games
FrodaN2999
Grubby1731
Beastyqt830
hiko719
RotterdaM252
ArmadaUGS157
Mew2King134
Hui .124
C9.Mang090
QueenE85
Trikslyr66
Organizations
StarCraft 2
angryscii 7
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 22 non-featured ]
StarCraft 2
• Reevou 20
• musti20045 4
• Kozan
• sooper7s
• AfreecaTV YouTube
• Migwel
• LaughNgamezSOOP
• intothetv
• IndyKCrew
StarCraft: Brood War
• HerbMon 13
• STPLYoutube
• ZZZeroYoutube
• BSLYoutube
Dota 2
• C_a_k_e 2719
• masondota21035
• lizZardDota242
• Noizen33
League of Legends
• Nemesis4360
• TFBlade823
Other Games
• imaqtpie1000
• WagamamaTV465
• Shiphtur279
Upcoming Events
PiGosaur Monday
5h 48m
Wardi Open
16h 48m
StarCraft2.fi
21h 48m
Replay Cast
1d 4h
The PondCast
1d 14h
Replay Cast
2 days
Korean StarCraft League
3 days
CranKy Ducklings
3 days
SC Evo League
3 days
BSL 21
4 days
Sziky vs OyAji
Gypsy vs eOnzErG
[ Show More ]
OSC
4 days
Solar vs Creator
ByuN vs Gerald
Percival vs Babymarine
Moja vs Krystianer
EnDerr vs ForJumy
sebesdes vs Nicoract
Sparkling Tuna Cup
4 days
OSC
4 days
BSL 21
5 days
Bonyth vs StRyKeR
Tarson vs Dandy
Replay Cast
5 days
Wardi Open
5 days
StarCraft2.fi
5 days
Replay Cast
6 days
StarCraft2.fi
6 days
Liquipedia Results

Completed

Proleague 2025-11-28
RSL Revival: Season 3
Light HT

Ongoing

C-Race Season 1
IPSL Winter 2025-26
KCM Race Survival 2025 Season 4
YSL S2
BSL Season 21
CSCL: Masked Kings S3
Slon Tour Season 2
Acropolis #4 - TS3
META Madness #9
SL Budapest Major 2025
ESL Impact League Season 8
BLAST Rivals Fall 2025
IEM Chengdu 2025
PGL Masters Bucharest 2025
Thunderpick World Champ.
CS Asia Championships 2025
ESL Pro League S22
StarSeries Fall 2025
FISSURE Playground #2

Upcoming

BSL 21 Non-Korean Championship
Acropolis #4
IPSL Spring 2026
Bellum Gens Elite Stara Zagora 2026
HSC XXVIII
RSL Offline Finals
WardiTV 2025
Kuram Kup
PGL Cluj-Napoca 2026
IEM Kraków 2026
BLAST Bounty Winter 2026
BLAST Bounty Winter Qual
eXTREMESLAND 2025
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.