• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EST 21:23
CET 03:23
KST 11:23
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
Rongyi Cup S3 - RO16 Preview1herO wins SC2 All-Star Invitational10SC2 All-Star Invitational: Tournament Preview5RSL Revival - 2025 Season Finals Preview8RSL Season 3 - Playoffs Preview0
Community News
Weekly Cups (Jan 12-18): herO, MaxPax, Solar win0BSL Season 2025 - Full Overview and Conclusion8Weekly Cups (Jan 5-11): Clem wins big offline, Trigger upsets4$21,000 Rongyi Cup Season 3 announced (Jan 22-Feb 7)17Weekly Cups (Dec 29-Jan 4): Protoss rolls, 2v2 returns7
StarCraft 2
General
Rongyi Cup S3 - RO16 Preview Starcraft 2 will not be in the Esports World Cup herO wins SC2 All-Star Invitational PhD study /w SC2 - help with a survey! SC2 Spotted on the EWC 2026 list?
Tourneys
$21,000 Rongyi Cup Season 3 announced (Jan 22-Feb 7) OSC Season 13 World Championship $70 Prize Pool Ladder Legends Academy Weekly Open! SC2 All-Star Invitational: Jan 17-18 Sparkling Tuna Cup - Weekly Open Tournament
Strategy
Simple Questions Simple Answers
Custom Maps
[A] Starcraft Sound Mod
External Content
Mutation # 509 Doomsday Report Mutation # 508 Violent Night Mutation # 507 Well Trained Mutation # 506 Warp Zone
Brood War
General
Which foreign pros are considered the best? [ASL21] Potential Map Candidates BW General Discussion BW AKA finder tool Gypsy to Korea
Tourneys
[Megathread] Daily Proleagues [BSL21] Non-Korean Championship - Starts Jan 10 Small VOD Thread 2.0 Azhi's Colosseum - Season 2
Strategy
Current Meta Simple Questions, Simple Answers Soma's 9 hatch build from ASL Game 2 Game Theory for Starcraft
Other Games
General Games
Battle Aces/David Kim RTS Megathread Nintendo Switch Thread Stormgate/Frost Giant Megathread Beyond All Reason Awesome Games Done Quick 2026!
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
Vanilla Mini Mafia Mafia Game Mode Feedback/Ideas
Community
General
US Politics Mega-thread Russo-Ukrainian War Thread NASA and the Private Sector Canadian Politics Mega-thread Things Aren’t Peaceful in Palestine
Fan Clubs
The herO Fan Club! The IdrA Fan Club
Media & Entertainment
Anime Discussion Thread [Manga] One Piece
Sports
2024 - 2026 Football Thread
World Cup 2022
Tech Support
Computer Build, Upgrade & Buying Resource Thread
TL Community
The Automated Ban List
Blogs
Navigating the Risks and Rew…
TrAiDoS
My 2025 Magic: The Gathering…
DARKING
Life Update and thoughts.
FuDDx
How do archons sleep?
8882
James Bond movies ranking - pa…
Topin
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1851 users

The Darkhotel APT

Blogs > Blazinghand
Post a Reply
Blazinghand *
Profile Blog Joined December 2010
United States25557 Posts
December 06 2014 11:33 GMT
#1
The Darkhotel APT





Kastersky has identified hacking activities that target powerful executives and business personnel around the world by infecting hotel networks. Some exerpts:

Moreover, this crew's most unusual characteristic is that for several years the Darkhotel APT has maintained a capability to use hotel networks to follow and hit selected targets as they travel around the world. These travelers are often top executives from a variety of industries doing business and outsourcing in the APAC region. Targets have included CEOs, senior vice presidents, sales and marketing directors and top R&D staff. This hotel network intrusion set provides the attackers with precise global scale access to high value targets.

[...]

Victim categories include the following verticals:
  • Very large electronics manufacturing
  • Investment capital and private equity
  • Pharmaceuticals
  • Cosmetics and chemicals manufacturing offshoring and sales
  • Automotive manufacturer offshoring services
  • Automotive assembly, distribution, sales, and services
  • Defense industrial base
  • Law enforcement and military services
  • Non-governmental organizations


[...]

When Kaspersky Lab researchers visited Darkhotel incident destinations with honeypot machines they did not attract Darkhotel attacks, which suggests the APT acts selectively.. Further work demonstrated just how careful these attackers were to hide their activity - as soon as a target was effectively infected, they deleted their tools from the hotel network staging point, maintaining a hidden status.


Read the rest of the article: https://securelist.com/blog/research/66779/the-darkhotel-apt/

Or the paper itself: https://securelist.com/files/2014/11/darkhotel_kl_07.11.pdf

It's interesting to read about just how vulnerable we really are to this sort of thing. How often do we click through the warnings when we connect to a public or unsecured network? Although at least one step involves tricking people into installing software, it looks like they may have used some particularly good ruses (tricking certificate authorities, or using 0-day vulnerabilities in Adobe Flash updater) to get their software onto the computers.

I'm pretty careful to use 2-step verification for email, not install random internet shit, and run virus scans fairly regularly. I wonder if there's more I should be doing to make sure I don't get hoodwinked, though. I'm not a high value target (it looks like this group selectively targeted business execs) so I don't have to worry much. What about you? what do you do to keep your computer secure?

***
When you stare into the iCCup, the iCCup stares back.
TL+ Member
Stratos
Profile Blog Joined July 2010
Czech Republic6104 Posts
December 06 2014 12:32 GMT
#2
On December 06 2014 20:33 Blazinghand wrote:
What about you? what do you do to keep your computer secure?

Nothing. I live in constant fear someone may find out I still watch Xena on a daily basis.
En Taro Violet
Deleuze
Profile Blog Joined December 2010
United Kingdom2102 Posts
December 06 2014 13:40 GMT
#3
I like the way that the video misrepresents the hacker as a tattooed punk whereas the reality is that they are just the same as the execs upon whom they prey.
“An image of thought called philosophy has been formed historically and it effectively stops people from thinking.” ― Gilles Deleuze, Dialogues II
Blazinghand *
Profile Blog Joined December 2010
United States25557 Posts
December 06 2014 14:31 GMT
#4
On December 06 2014 22:40 Deleuze wrote:
I like the way that the video misrepresents the hacker as a tattooed punk whereas the reality is that they are just the same as the execs upon whom they prey.

the goggles are the best part
When you stare into the iCCup, the iCCup stares back.
TL+ Member
Gamegene
Profile Blog Joined June 2011
United States8308 Posts
December 06 2014 23:26 GMT
#5
(Completely uninformed about subject)

Is this malware being exclusively use for one party's benefit or is it being used as a tool by several different parties targeting the same interest groups in different countries?

The loot sounds like the stuff various governments (China?) would love to get their fingers on.
Throw on your favorite jacket and you're good to roll. Stroll through the trees and let your miseries go.
Please log in or register to reply.
Live Events Refresh
Next event in 8h 37m
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
PiGStarcraft430
Nathanias 96
StarCraft: Brood War
Artosis 617
Shuttle 64
Bale 54
Noble 15
Dota 2
NeuroSwarm12
League of Legends
C9.Mang0402
Counter-Strike
taco 306
minikerr24
Super Smash Bros
hungrybox1114
Other Games
summit1g6832
tarik_tv6397
KnowMe1271
JimRising 395
Maynarde125
ToD97
ViBE33
ZombieGrub7
Organizations
Other Games
gamesdonequick1028
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 16 non-featured ]
StarCraft 2
• Hupsaiya 104
• Berry_CruncH40
• AfreecaTV YouTube
• intothetv
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Laughngamez YouTube
• Migwel
• sooper7s
StarCraft: Brood War
• RayReign 33
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
Dota 2
• masondota21162
League of Legends
• Doublelift4999
Upcoming Events
RongYI Cup
8h 37m
ByuN vs TriGGeR
herO vs Rogue
OSC
8h 37m
herO vs Clem
Cure vs TBD
Solar vs TBD
Classic vs TBD
RongYI Cup
1d 8h
Clem vs ShoWTimE
Zoun vs Bunny
Big Brain Bouts
1d 14h
Serral vs TBD
RongYI Cup
2 days
SHIN vs Creator
Classic vs Percival
OSC
2 days
BSL 21
2 days
RongYI Cup
3 days
Maru vs Cyan
Solar vs Krystianer
uThermal 2v2 Circuit
3 days
BSL 21
3 days
[ Show More ]
Wardi Open
4 days
Monday Night Weeklies
4 days
OSC
4 days
WardiTV Invitational
5 days
WardiTV Invitational
6 days
Liquipedia Results

Completed

Proleague 2026-01-20
SC2 All-Star Inv. 2025
NA Kuram Kup

Ongoing

C-Race Season 1
BSL 21 Non-Korean Championship
CSL 2025 WINTER (S19)
KCM Race Survival 2026 Season 1
Rongyi Cup S3
OSC Championship Season 13
Underdog Cup #3
BLAST Bounty Winter 2026
BLAST Bounty Winter Qual
eXTREMESLAND 2025
SL Budapest Major 2025
ESL Impact League Season 8
BLAST Rivals Fall 2025
IEM Chengdu 2025

Upcoming

Escore Tournament S1: W5
Acropolis #4 - TS4
Acropolis #4
IPSL Spring 2026
uThermal 2v2 2026 Main Event
Bellum Gens Elite Stara Zagora 2026
HSC XXVIII
Nations Cup 2026
PGL Bucharest 2026
Stake Ranked Episode 1
BLAST Open Spring 2026
ESL Pro League Season 23
ESL Pro League Season 23
PGL Cluj-Napoca 2026
IEM Kraków 2026
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2026 TLnet. All Rights Reserved.