• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 10:42
CEST 16:42
KST 23:42
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
[ASL20] Ro24 Preview Pt1: Runway112v2 & SC: Evo Complete: Weekend Double Feature2Team Liquid Map Contest #21 - Presented by Monster Energy9uThermal's 2v2 Tour: $15,000 Main Event18Serral wins EWC 202549
Community News
Weekly Cups (Aug 11-17): MaxPax triples again!9Weekly Cups (Aug 4-10): MaxPax wins a triple6SC2's Safe House 2 - October 18 & 195Weekly Cups (Jul 28-Aug 3): herO doubles up6LiuLi Cup - August 2025 Tournaments7
StarCraft 2
General
What mix of new and old maps do you want in the next 1v1 ladder pool? (SC2) : RSL Revival patreon money discussion thread Weekly Cups (Aug 11-17): MaxPax triples again! Team Liquid Map Contest #21 - Presented by Monster Energy Would you prefer the game to be balanced around top-tier pro level or average pro level?
Tourneys
Sparkling Tuna Cup - Weekly Open Tournament RSL: Revival, a new crowdfunded tournament series LiuLi Cup - August 2025 Tournaments SEL Masters #5 - Korea vs Russia (SC Evo) Enki Epic Series #5 - TaeJa vs Classic (SC Evo)
Strategy
Custom Maps
External Content
Mutation # 487 Think Fast Mutation # 486 Watch the Skies Mutation # 485 Death from Below Mutation # 484 Magnetic Pull
Brood War
General
ASL 20 HYPE VIDEO! Flash Announces (and Retracts) Hiatus From ASL BW General Discussion New season has just come in ladder [ASL20] Ro24 Preview Pt1: Runway
Tourneys
[ASL20] Ro24 Group B [Megathread] Daily Proleagues [ASL20] Ro24 Group A BWCL Season 63 Announcement
Strategy
Simple Questions, Simple Answers Fighting Spirit mining rates [G] Mineral Boosting Muta micro map competition
Other Games
General Games
Stormgate/Frost Giant Megathread Nintendo Switch Thread Total Annihilation Server - TAForever Beyond All Reason [MMORPG] Tree of Savior (Successor of Ragnarok)
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread Vanilla Mini Mafia
Community
General
US Politics Mega-thread Russo-Ukrainian War Thread Things Aren’t Peaceful in Palestine European Politico-economics QA Mega-thread The Games Industry And ATVI
Fan Clubs
INnoVation Fan Club SKT1 Classic Fan Club!
Media & Entertainment
Anime Discussion Thread Movie Discussion! [Manga] One Piece [\m/] Heavy Metal Thread
Sports
2024 - 2026 Football Thread TeamLiquid Health and Fitness Initiative For 2023 Formula 1 Discussion
World Cup 2022
Tech Support
Gtx660 graphics card replacement Installation of Windows 10 suck at "just a moment" Computer Build, Upgrade & Buying Resource Thread
TL Community
TeamLiquid Team Shirt On Sale The Automated Ban List
Blogs
The Biochemical Cost of Gami…
TrAiDoS
[Girl blog} My fema…
artosisisthebest
Sharpening the Filtration…
frozenclaw
ASL S20 English Commentary…
namkraft
StarCraft improvement
iopq
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1320 users

The Darkhotel APT

Blogs > Blazinghand
Post a Reply
Blazinghand *
Profile Blog Joined December 2010
United States25552 Posts
December 06 2014 11:33 GMT
#1
The Darkhotel APT





Kastersky has identified hacking activities that target powerful executives and business personnel around the world by infecting hotel networks. Some exerpts:

Moreover, this crew's most unusual characteristic is that for several years the Darkhotel APT has maintained a capability to use hotel networks to follow and hit selected targets as they travel around the world. These travelers are often top executives from a variety of industries doing business and outsourcing in the APAC region. Targets have included CEOs, senior vice presidents, sales and marketing directors and top R&D staff. This hotel network intrusion set provides the attackers with precise global scale access to high value targets.

[...]

Victim categories include the following verticals:
  • Very large electronics manufacturing
  • Investment capital and private equity
  • Pharmaceuticals
  • Cosmetics and chemicals manufacturing offshoring and sales
  • Automotive manufacturer offshoring services
  • Automotive assembly, distribution, sales, and services
  • Defense industrial base
  • Law enforcement and military services
  • Non-governmental organizations


[...]

When Kaspersky Lab researchers visited Darkhotel incident destinations with honeypot machines they did not attract Darkhotel attacks, which suggests the APT acts selectively.. Further work demonstrated just how careful these attackers were to hide their activity - as soon as a target was effectively infected, they deleted their tools from the hotel network staging point, maintaining a hidden status.


Read the rest of the article: https://securelist.com/blog/research/66779/the-darkhotel-apt/

Or the paper itself: https://securelist.com/files/2014/11/darkhotel_kl_07.11.pdf

It's interesting to read about just how vulnerable we really are to this sort of thing. How often do we click through the warnings when we connect to a public or unsecured network? Although at least one step involves tricking people into installing software, it looks like they may have used some particularly good ruses (tricking certificate authorities, or using 0-day vulnerabilities in Adobe Flash updater) to get their software onto the computers.

I'm pretty careful to use 2-step verification for email, not install random internet shit, and run virus scans fairly regularly. I wonder if there's more I should be doing to make sure I don't get hoodwinked, though. I'm not a high value target (it looks like this group selectively targeted business execs) so I don't have to worry much. What about you? what do you do to keep your computer secure?

***
When you stare into the iCCup, the iCCup stares back.
TL+ Member
Stratos
Profile Blog Joined July 2010
Czech Republic6104 Posts
December 06 2014 12:32 GMT
#2
On December 06 2014 20:33 Blazinghand wrote:
What about you? what do you do to keep your computer secure?

Nothing. I live in constant fear someone may find out I still watch Xena on a daily basis.
En Taro Violet
Deleuze
Profile Blog Joined December 2010
United Kingdom2102 Posts
December 06 2014 13:40 GMT
#3
I like the way that the video misrepresents the hacker as a tattooed punk whereas the reality is that they are just the same as the execs upon whom they prey.
“An image of thought called philosophy has been formed historically and it effectively stops people from thinking.” ― Gilles Deleuze, Dialogues II
Blazinghand *
Profile Blog Joined December 2010
United States25552 Posts
December 06 2014 14:31 GMT
#4
On December 06 2014 22:40 Deleuze wrote:
I like the way that the video misrepresents the hacker as a tattooed punk whereas the reality is that they are just the same as the execs upon whom they prey.

the goggles are the best part
When you stare into the iCCup, the iCCup stares back.
TL+ Member
Gamegene
Profile Blog Joined June 2011
United States8308 Posts
December 06 2014 23:26 GMT
#5
(Completely uninformed about subject)

Is this malware being exclusively use for one party's benefit or is it being used as a tool by several different parties targeting the same interest groups in different countries?

The loot sounds like the stuff various governments (China?) would love to get their fingers on.
Throw on your favorite jacket and you're good to roll. Stroll through the trees and let your miseries go.
Please log in or register to reply.
Live Events Refresh
WardiTV Summer Champion…
11:00
Group Stage 2 - Group A
Creator vs Rogue
MaxPax vs Cure
WardiTV1296
Harstem462
IndyStarCraft 201
Rex185
Liquipedia
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
Harstem 462
Hui .213
IndyStarCraft 201
Rex 185
ProTech65
mcanning 62
Codebar 45
SC2_NightMare 8
StarCraft: Brood War
Britney 50148
Rain 7666
Calm 5627
Flash 2983
Jaedong 1799
Horang2 1280
EffOrt 810
ggaemo 797
BeSt 597
Larva 412
[ Show more ]
Snow 397
ZerO 308
Soulkey 291
Light 285
Barracks 243
firebathero 240
hero 232
Rush 146
Hyuk 124
Mong 111
Hyun 84
Mind 60
Killer 60
Backho 58
Movie 54
Sharp 48
ToSsGirL 46
soO 30
ajuk12(nOOB) 19
Sacsri 18
Terrorterran 15
Noble 12
yabsab 10
HiyA 7
Dota 2
Gorgc9492
qojqva1928
Dendi1361
XcaliburYe220
Super Smash Bros
Westballz45
Heroes of the Storm
Trikslyr55
Other Games
singsing1998
B2W.Neo1624
hiko1317
crisheroes540
FrodaN421
Lowko386
DeMusliM244
ArmadaUGS174
XaKoH 142
Liquid`VortiX109
QueenE62
ZerO(Twitch)17
Organizations
StarCraft: Brood War
Kim Chul Min (afreeca) 8
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 15 non-featured ]
StarCraft 2
• poizon28 13
• intothetv
• AfreecaTV YouTube
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Migwel
• sooper7s
StarCraft: Brood War
• Azhi_Dahaki31
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
Dota 2
• C_a_k_e 2344
League of Legends
• Nemesis6260
Other Games
• WagamamaTV233
Upcoming Events
PiGosaur Monday
9h 18m
Afreeca Starleague
19h 18m
Mini vs TBD
Soma vs sSak
WardiTV Summer Champion…
20h 18m
Clem vs goblin
ByuN vs SHIN
Online Event
1d 9h
The PondCast
1d 19h
WardiTV Summer Champion…
1d 20h
Zoun vs Bunny
herO vs Solar
Replay Cast
2 days
LiuLi Cup
2 days
BSL Team Wars
3 days
Team Hawk vs Team Dewalt
Korean StarCraft League
3 days
[ Show More ]
CranKy Ducklings
3 days
SC Evo League
3 days
WardiTV Summer Champion…
3 days
Classic vs Percival
Spirit vs NightMare
[BSL 2025] Weekly
4 days
Sparkling Tuna Cup
4 days
SC Evo League
4 days
BSL Team Wars
5 days
Team Bonyth vs Team Sziky
Afreeca Starleague
5 days
Queen vs HyuN
EffOrt vs Calm
Wardi Open
5 days
Replay Cast
6 days
Afreeca Starleague
6 days
Rush vs TBD
Jaedong vs Mong
Liquipedia Results

Completed

Jiahua Invitational
uThermal 2v2 Main Event
HCC Europe

Ongoing

Copa Latinoamericana 4
BSL 20 Team Wars
KCM Race Survival 2025 Season 3
BSL 21 Qualifiers
ASL Season 20
CSL Season 18: Qualifier 1
SEL Season 2 Championship
WardiTV Summer 2025
BLAST Bounty Fall 2025
BLAST Bounty Fall Qual
IEM Cologne 2025
FISSURE Playground #1
BLAST.tv Austin Major 2025

Upcoming

CSLAN 3
CSL 2025 AUTUMN (S18)
LASL Season 20
BSL Season 21
BSL 21 Team A
RSL Revival: Season 2
Maestros of the Game
EC S1
PGL Masters Bucharest 2025
Thunderpick World Champ.
MESA Nomadic Masters Fall
CS Asia Championships 2025
Roobet Cup 2025
ESL Pro League S22
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025
BLAST Open Fall Qual
Esports World Cup 2025
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.