• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 12:04
CEST 18:04
KST 01:04
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
BGE Stara Zagora 2025: Info & Preview18Code S RO12 Preview: GuMiho, Bunny, SHIN, ByuN3The Memories We Share - Facing the Final(?) GSL46Code S RO12 Preview: Cure, Zoun, Solar, Creator4[ASL19] Finals Preview: Daunting Task30
Community News
[BSL20] ProLeague: Bracket Stage & Dates1GSL Ro4 and Finals moved to Sunday June 15th11Weekly Cups (May 27-June 1): ByuN goes back-to-back0EWC 2025 Regional Qualifier Results26Code S RO12 Results + RO8 Groups (2025 Season 2)3
StarCraft 2
General
Jim claims he and Firefly were involved in match-fixing Magnus Carlsen and Fabi review Clem's chess game. BGE Stara Zagora 2025: Info & Preview GSL Ro4 and Finals moved to Sunday June 15th Serious Question: Mech
Tourneys
SOOPer7s Showmatches 2025 Bellum Gens Elite: Stara Zagora 2025 Cheeseadelphia 2025 - Open Bracket LAN! $25,000+ WardiTV 2025 Series Sparkling Tuna Cup - Weekly Open Tournament
Strategy
[G] Darkgrid Layout Simple Questions Simple Answers [G] PvT Cheese: 13 Gate Proxy Robo
Custom Maps
[UMS] Zillion Zerglings
External Content
Mutation # 476 Charnel House Mutation # 475 Hard Target Mutation # 474 Futile Resistance Mutation # 473 Cold is the Void
Brood War
General
Will foreigners ever be able to challenge Koreans? BGH auto balance -> http://bghmmr.eu/ [BSL20] ProLeague: Bracket Stage & Dates I made an ASL quiz BW General Discussion
Tourneys
[Megathread] Daily Proleagues [ASL19] Grand Finals Small VOD Thread 2.0 [BSL20] GosuLeague RO16 - Tue & Wed 20:00+CET
Strategy
I am doing this better than progamers do. [G] How to get started on ladder as a new Z player
Other Games
General Games
Mechabellum Nintendo Switch Thread Stormgate/Frost Giant Megathread Monster Hunter Wilds Path of Exile
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
LiquidLegends to reintegrate into TL.net
Heroes of the Storm
Simple Questions, Simple Answers
Hearthstone
Heroes of StarCraft mini-set
TL Mafia
Vanilla Mini Mafia TL Mafia Community Thread
Community
General
US Politics Mega-thread Russo-Ukrainian War Thread Things Aren’t Peaceful in Palestine Vape Nation Thread European Politico-economics QA Mega-thread
Fan Clubs
Maru Fan Club Serral Fan Club
Media & Entertainment
Korean Music Discussion [Manga] One Piece
Sports
2024 - 2025 Football Thread Formula 1 Discussion NHL Playoffs 2024
World Cup 2022
Tech Support
Computer Build, Upgrade & Buying Resource Thread Cleaning My Mechanical Keyboard
TL Community
The Automated Ban List
Blogs
Heero Yuy & the Tax…
KrillinFromwales
Research study on team perfo…
TrAiDoS
I was completely wrong ab…
jameswatts
Need Your Help/Advice
Glider
Trip to the Zoo
micronesia
Poker
Nebuchad
Info SLEgma_12
SLEgma_12
Customize Sidebar...

Website Feedback

Closed Threads



Active: 15344 users

The Darkhotel APT

Blogs > Blazinghand
Post a Reply
Blazinghand *
Profile Blog Joined December 2010
United States25550 Posts
December 06 2014 11:33 GMT
#1
The Darkhotel APT





Kastersky has identified hacking activities that target powerful executives and business personnel around the world by infecting hotel networks. Some exerpts:

Moreover, this crew's most unusual characteristic is that for several years the Darkhotel APT has maintained a capability to use hotel networks to follow and hit selected targets as they travel around the world. These travelers are often top executives from a variety of industries doing business and outsourcing in the APAC region. Targets have included CEOs, senior vice presidents, sales and marketing directors and top R&D staff. This hotel network intrusion set provides the attackers with precise global scale access to high value targets.

[...]

Victim categories include the following verticals:
  • Very large electronics manufacturing
  • Investment capital and private equity
  • Pharmaceuticals
  • Cosmetics and chemicals manufacturing offshoring and sales
  • Automotive manufacturer offshoring services
  • Automotive assembly, distribution, sales, and services
  • Defense industrial base
  • Law enforcement and military services
  • Non-governmental organizations


[...]

When Kaspersky Lab researchers visited Darkhotel incident destinations with honeypot machines they did not attract Darkhotel attacks, which suggests the APT acts selectively.. Further work demonstrated just how careful these attackers were to hide their activity - as soon as a target was effectively infected, they deleted their tools from the hotel network staging point, maintaining a hidden status.


Read the rest of the article: https://securelist.com/blog/research/66779/the-darkhotel-apt/

Or the paper itself: https://securelist.com/files/2014/11/darkhotel_kl_07.11.pdf

It's interesting to read about just how vulnerable we really are to this sort of thing. How often do we click through the warnings when we connect to a public or unsecured network? Although at least one step involves tricking people into installing software, it looks like they may have used some particularly good ruses (tricking certificate authorities, or using 0-day vulnerabilities in Adobe Flash updater) to get their software onto the computers.

I'm pretty careful to use 2-step verification for email, not install random internet shit, and run virus scans fairly regularly. I wonder if there's more I should be doing to make sure I don't get hoodwinked, though. I'm not a high value target (it looks like this group selectively targeted business execs) so I don't have to worry much. What about you? what do you do to keep your computer secure?

***
When you stare into the iCCup, the iCCup stares back.
TL+ Member
Stratos
Profile Blog Joined July 2010
Czech Republic6104 Posts
December 06 2014 12:32 GMT
#2
On December 06 2014 20:33 Blazinghand wrote:
What about you? what do you do to keep your computer secure?

Nothing. I live in constant fear someone may find out I still watch Xena on a daily basis.
En Taro Violet
Deleuze
Profile Blog Joined December 2010
United Kingdom2102 Posts
December 06 2014 13:40 GMT
#3
I like the way that the video misrepresents the hacker as a tattooed punk whereas the reality is that they are just the same as the execs upon whom they prey.
“An image of thought called philosophy has been formed historically and it effectively stops people from thinking.” ― Gilles Deleuze, Dialogues II
Blazinghand *
Profile Blog Joined December 2010
United States25550 Posts
December 06 2014 14:31 GMT
#4
On December 06 2014 22:40 Deleuze wrote:
I like the way that the video misrepresents the hacker as a tattooed punk whereas the reality is that they are just the same as the execs upon whom they prey.

the goggles are the best part
When you stare into the iCCup, the iCCup stares back.
TL+ Member
Gamegene
Profile Blog Joined June 2011
United States8308 Posts
December 06 2014 23:26 GMT
#5
(Completely uninformed about subject)

Is this malware being exclusively use for one party's benefit or is it being used as a tool by several different parties targeting the same interest groups in different countries?

The loot sounds like the stuff various governments (China?) would love to get their fingers on.
Throw on your favorite jacket and you're good to roll. Stroll through the trees and let your miseries go.
Please log in or register to reply.
Live Events Refresh
Bellum Gens Elite
10:00
Stara Zagora 2025 Day 2
Lambo vs YoungYakovLIVE!
Bellum Gens Elite1450
ComeBackTV 555
TaKeTV 308
IndyStarCraft 275
Rex151
3DClanTV 115
CosmosSc2 93
LiquipediaDiscussion
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
Bellum Gens Elite1450
IndyStarCraft 275
Rex 151
CosmosSc2 93
StarCraft: Brood War
Britney 30951
Sea 2732
EffOrt 1339
ZerO 1097
PianO 936
Mini 854
BeSt 853
Stork 469
Light 345
Snow 310
[ Show more ]
firebathero 273
hero 204
Dewaltoss 143
Rush 138
sSak 84
Zeus 81
sas.Sziky 46
Movie 45
Sacsri 43
Free 35
soO 30
Shinee 25
sorry 25
ajuk12(nOOB) 16
yabsab 13
scan(afreeca) 13
Backho 7
Noble 7
Bale 4
Shine 2
Dota 2
Gorgc6704
qojqva3144
XcaliburYe390
Fuzer 276
syndereN265
BabyKnight37
League of Legends
Dendi826
Counter-Strike
fl0m4597
olofmeister2380
rGuardiaN71
edward40
Super Smash Bros
Mew2King77
Chillindude26
Heroes of the Storm
Khaldor107
Other Games
singsing2078
FrodaN1001
B2W.Neo998
crisheroes533
Lowko309
Happy270
ceh9151
ArmadaUGS118
QueenE55
Trikslyr52
KnowMe46
XaKoH 34
ZerO(Twitch)24
Has12
Organizations
Dota 2
PGL Dota 2 - Main Stream3881
PGL Dota 2 - Secondary Stream159
StarCraft: Brood War
Kim Chul Min (afreeca) 9
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 13 non-featured ]
StarCraft 2
• AfreecaTV YouTube
• intothetv
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Migwel
• sooper7s
StarCraft: Brood War
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
Dota 2
• C_a_k_e 5234
League of Legends
• Nemesis3007
• Jankos1604
Upcoming Events
Replay Cast
7h 57m
OSC
7h 57m
Bellum Gens Elite
17h 57m
WardiTV Invitational
21h 57m
BSL 2v2 ProLeague
1d 2h
Replay Cast
1d 7h
CranKy Ducklings
1d 17h
SC Evo League
1d 19h
Bellum Gens Elite
1d 20h
Fire Grow Cup
1d 22h
[ Show More ]
CSO Contender
2 days
BSL: ProLeague
2 days
StRyKeR vs MadiNho
Cross vs UltrA
TT1 vs JDConan
Bonyth vs Sziky
Replay Cast
2 days
SOOP Global
2 days
Creator vs Rogue
Cure vs Classic
SOOP
2 days
SHIN vs GuMiho
Sparkling Tuna Cup
2 days
AllThingsProtoss
2 days
Fire Grow Cup
2 days
BSL: ProLeague
3 days
HBO vs Doodle
spx vs Tech
DragOn vs Hawk
Dewalt vs TerrOr
Replay Cast
3 days
Replay Cast
4 days
Replay Cast
4 days
WardiTV Invitational
4 days
WardiTV Invitational
4 days
GSL Code S
5 days
Rogue vs GuMiho
Maru vs Solar
Replay Cast
6 days
GSL Code S
6 days
herO vs TBD
Classic vs TBD
The PondCast
6 days
Liquipedia Results

Completed

CSL Season 17: Qualifier 1
DreamHack Dallas 2025
Heroes 10 EU

Ongoing

JPL Season 2
BSL 2v2 Season 3
BSL Season 20
KCM Race Survival 2025 Season 2
NPSL S3
Rose Open S1
CSL Season 17: Qualifier 2
2025 GSL S2
BGE Stara Zagora 2025
BLAST.tv Austin Major 2025
ESL Impact League Season 7
IEM Dallas 2025
PGL Astana 2025
Asian Champions League '25
ECL Season 49: Europe
BLAST Rivals Spring 2025
MESA Nomadic Masters
CCT Season 2 Global Finals
IEM Melbourne 2025
YaLLa Compass Qatar 2025
PGL Bucharest 2025
BLAST Open Spring 2025

Upcoming

CSL 17: 2025 SUMMER
Copa Latinoamericana 4
CSLPRO Last Chance 2025
CSLPRO Chat StarLAN 3
K-Championship
SEL Season 2 Championship
Esports World Cup 2025
HSC XXVII
Championship of Russia 2025
Murky Cup #2
NC Random Cup
BLAST Bounty Fall 2025
BLAST Bounty Fall Qual
IEM Cologne 2025
FISSURE Playground #1
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.