Netskope Threat Labs

DarkHotel

ATP Sandbox Adv. HeuristicsAV

DarkHotel is a malware implant family associated with the DarkHotel threat actor, which researchers also track as DUBNIUM. Kaspersky documented the group's 2015 attacks, Microsoft published reverse engineering of the DUBNIUM implants, and JPCERT described the Asruex variant that infects systems through shortcut files. Reuters reported that the actor targeted the World Health Organization during the 2020 spike in coronavirus related cyberattacks.

First seen
March 2022
Last seen
October 2026
Darkhotel
Alert Name
Gen:Variant.DarkHotel.18
Gen:Variant.DarkHotel.2
Gen:Variant.DarkHotel.26
Gen:Variant.DarkHotel.8
Win32.Backdoor.DarkHotel
Win32.Spyware.Darkhotel
Win32.Spyware.DarkHotel
Win32.Trojan.DarkHotel