Kaspersky described DarkHotel in a 2014 report as: '... DarkHotel drives its campaigns by spear-phishing targets with highly advanced Flash zero-day e...

Threat Actor Profile

DarkHotel

State-sponsored threat group originating from KR. Suspected sponsor: Korea (Republic of). Known to target Private sector.

1 Industries Tracked Real-Time Alerts

Actor Overview

Origin Country
KR
Suspected Sponsor
Korea (Republic of)
Incident Types
Espionage

Target Industries

Private sector

Suspected Victims

JapanRussiaTaiwanSouth KoreaChina

Related Threat Reports

Premium
APT Campaign Analysis - Q4 2025Dec 2025
New Tactics Observed in WildDec 2025
Infrastructure Mapping ReportDec 2025
Stay Updated

Get alerts when new intel on DarkHotel is published.

Actor Details

Primary Name
DarkHotel
Known Aliases
DUBNIUM, Fallout Team, Karba, Luder, Nemim, Nemin, Tapaoux, Pioneer, Shadow Crane, APT-C-06, SIG25, TUNGSTEN BRIDGE, T-APT-02, G0012, ATK52, Zigzag Hail
Data Source
Precursor Intelligence
Need API Access?

Integrate threat actor data into your SIEM or SOAR.

View Plans →