• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 21:55
CEST 03:55
KST 10:55
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
TL.net Map Contest #21: Voting5[ASL20] Ro4 Preview: Descent11Team TLMC #5: Winners Announced!3[ASL20] Ro8 Preview Pt2: Holding On9Maestros of the Game: Live Finals Preview (RO4)5
Community News
Weekly Cups (Oct 6-12): Four star herO65.0.15 Patch Balance Hotfix (2025-10-8)74Weekly Cups (Sept 29-Oct 5): MaxPax triples up3PartinG joins SteamerZone, returns to SC2 competition325.0.15 Balance Patch Notes (Live version)119
StarCraft 2
General
TL.net Map Contest #21: Voting 5.0.15 Patch Balance Hotfix (2025-10-8) The New Patch Killed Mech! Ladder Impersonation (only maybe) Weekly Cups (Oct 6-12): Four star herO
Tourneys
LiuLi Cup - September 2025 Tournaments Sparkling Tuna Cup - Weekly Open Tournament Master Swan Open (Global Bronze-Master 2) Tenacious Turtle Tussle WardiTV Mondays
Strategy
Custom Maps
External Content
Mutation # 495 Rest In Peace Mutation # 494 Unstable Environment Mutation # 493 Quick Killers Mutation # 492 Get Out More
Brood War
General
After 20 seasons we have a lot of great maps Pros React To: BarrackS + FlaSh Coaching vs SnOw Whose hotkey signature is this? BW caster Sayle BW General Discussion
Tourneys
[Megathread] Daily Proleagues [ASL20] Semifinal A [ASL20] Semifinal B [ASL20] Ro8 Day 4
Strategy
Current Meta BW - ajfirecracker Strategy & Training Siegecraft - a new perspective TvZ Theorycraft - Improving on State of the Art
Other Games
General Games
Stormgate/Frost Giant Megathread Nintendo Switch Thread ZeroSpace Megathread Dawn of War IV Path of Exile
Dota 2
Official 'what is Dota anymore' discussion LiquidDota to reintegrate into TL.net
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
SPIRED by.ASL Mafia {211640} TL Mafia Community Thread
Community
General
US Politics Mega-thread Things Aren’t Peaceful in Palestine Russo-Ukrainian War Thread Men's Fashion Thread Sex and weight loss
Fan Clubs
The herO Fan Club! The Happy Fan Club!
Media & Entertainment
[Manga] One Piece Anime Discussion Thread Movie Discussion!
Sports
2024 - 2026 Football Thread Formula 1 Discussion MLB/Baseball 2023 NBA General Discussion TeamLiquid Health and Fitness Initiative For 2023
World Cup 2022
Tech Support
SC2 Client Relocalization [Change SC2 Language] Linksys AE2500 USB WIFI keeps disconnecting Computer Build, Upgrade & Buying Resource Thread
TL Community
The Automated Ban List Recent Gifted Posts
Blogs
Inbreeding: Why Do We Do It…
Peanutsc
From Tilt to Ragequit:The Ps…
TrAiDoS
Customize Sidebar...

Website Feedback

Closed Threads



Active: 2053 users

The Darkhotel APT

Blogs > Blazinghand
Post a Reply
Blazinghand *
Profile Blog Joined December 2010
United States25553 Posts
December 06 2014 11:33 GMT
#1
The Darkhotel APT





Kastersky has identified hacking activities that target powerful executives and business personnel around the world by infecting hotel networks. Some exerpts:

Moreover, this crew's most unusual characteristic is that for several years the Darkhotel APT has maintained a capability to use hotel networks to follow and hit selected targets as they travel around the world. These travelers are often top executives from a variety of industries doing business and outsourcing in the APAC region. Targets have included CEOs, senior vice presidents, sales and marketing directors and top R&D staff. This hotel network intrusion set provides the attackers with precise global scale access to high value targets.

[...]

Victim categories include the following verticals:
  • Very large electronics manufacturing
  • Investment capital and private equity
  • Pharmaceuticals
  • Cosmetics and chemicals manufacturing offshoring and sales
  • Automotive manufacturer offshoring services
  • Automotive assembly, distribution, sales, and services
  • Defense industrial base
  • Law enforcement and military services
  • Non-governmental organizations


[...]

When Kaspersky Lab researchers visited Darkhotel incident destinations with honeypot machines they did not attract Darkhotel attacks, which suggests the APT acts selectively.. Further work demonstrated just how careful these attackers were to hide their activity - as soon as a target was effectively infected, they deleted their tools from the hotel network staging point, maintaining a hidden status.


Read the rest of the article: https://securelist.com/blog/research/66779/the-darkhotel-apt/

Or the paper itself: https://securelist.com/files/2014/11/darkhotel_kl_07.11.pdf

It's interesting to read about just how vulnerable we really are to this sort of thing. How often do we click through the warnings when we connect to a public or unsecured network? Although at least one step involves tricking people into installing software, it looks like they may have used some particularly good ruses (tricking certificate authorities, or using 0-day vulnerabilities in Adobe Flash updater) to get their software onto the computers.

I'm pretty careful to use 2-step verification for email, not install random internet shit, and run virus scans fairly regularly. I wonder if there's more I should be doing to make sure I don't get hoodwinked, though. I'm not a high value target (it looks like this group selectively targeted business execs) so I don't have to worry much. What about you? what do you do to keep your computer secure?

***
When you stare into the iCCup, the iCCup stares back.
TL+ Member
Stratos
Profile Blog Joined July 2010
Czech Republic6104 Posts
December 06 2014 12:32 GMT
#2
On December 06 2014 20:33 Blazinghand wrote:
What about you? what do you do to keep your computer secure?

Nothing. I live in constant fear someone may find out I still watch Xena on a daily basis.
En Taro Violet
Deleuze
Profile Blog Joined December 2010
United Kingdom2102 Posts
December 06 2014 13:40 GMT
#3
I like the way that the video misrepresents the hacker as a tattooed punk whereas the reality is that they are just the same as the execs upon whom they prey.
“An image of thought called philosophy has been formed historically and it effectively stops people from thinking.” ― Gilles Deleuze, Dialogues II
Blazinghand *
Profile Blog Joined December 2010
United States25553 Posts
December 06 2014 14:31 GMT
#4
On December 06 2014 22:40 Deleuze wrote:
I like the way that the video misrepresents the hacker as a tattooed punk whereas the reality is that they are just the same as the execs upon whom they prey.

the goggles are the best part
When you stare into the iCCup, the iCCup stares back.
TL+ Member
Gamegene
Profile Blog Joined June 2011
United States8308 Posts
December 06 2014 23:26 GMT
#5
(Completely uninformed about subject)

Is this malware being exclusively use for one party's benefit or is it being used as a tool by several different parties targeting the same interest groups in different countries?

The loot sounds like the stuff various governments (China?) would love to get their fingers on.
Throw on your favorite jacket and you're good to roll. Stroll through the trees and let your miseries go.
Please log in or register to reply.
Live Events Refresh
Replay Cast
23:00
PiGosaur Cup #53
Liquipedia
OSC
23:00
OSC Masters Cup #150 Qual #1
Liquipedia
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
RuFF_SC2 94
Ketroc 31
StarCraft: Brood War
Larva 1742
Leta 565
Sharp 40
Dota 2
monkeys_forever553
LuMiX1
League of Legends
JimRising 548
Counter-Strike
fl0m1608
PGG 83
Super Smash Bros
hungrybox472
Other Games
summit1g6899
shahzam644
Day[9].tv553
C9.Mang0291
ViBE235
Skadoodle189
Maynarde147
fpsfer 1
Organizations
Other Games
gamesdonequick1118
BasetradeTV155
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 17 non-featured ]
StarCraft 2
• Hupsaiya 48
• Kozan
• sooper7s
• AfreecaTV YouTube
• Migwel
• intothetv
• LaughNgamezSOOP
• IndyKCrew
StarCraft: Brood War
• STPLYoutube
• ZZZeroYoutube
• BSLYoutube
Dota 2
• WagamamaTV753
• Ler50
League of Legends
• Stunt213
• HappyZerGling167
Other Games
• Scarra613
• Day9tv553
Upcoming Events
The PondCast
8h 6m
OSC
10h 6m
Wardi Open
1d 9h
CranKy Ducklings
2 days
Safe House 2
2 days
Sparkling Tuna Cup
3 days
Safe House 2
3 days
Tenacious Turtle Tussle
6 days
Liquipedia Results

Completed

CSL 2025 AUTUMN (S18)
WardiTV TLMC #15
HCC Europe

Ongoing

BSL 21 Points
ASL Season 20
C-Race Season 1
IPSL Winter 2025-26
EC S1
Thunderpick World Champ.
CS Asia Championships 2025
ESL Pro League S22
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025
BLAST Open Fall Qual
Esports World Cup 2025
BLAST Bounty Fall 2025
BLAST Bounty Fall Qual
IEM Cologne 2025

Upcoming

SC4ALL: Brood War
BSL Season 21
BSL 21 Team A
RSL Offline Finals
RSL Revival: Season 3
Stellar Fest
SC4ALL: StarCraft II
eXTREMESLAND 2025
ESL Impact League Season 8
SL Budapest Major 2025
BLAST Rivals Fall 2025
IEM Chengdu 2025
PGL Masters Bucharest 2025
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.