DarkHotel is a long-running espionage malware operation and associated spyware toolkit known for targeting Windows systems, particularly in high-value intrusion campaigns. It has been linked in public reporting to the DarkHotel threat cluster and is frequently discussed in the context of targeted surveillance activity against business travelers, government-related targets, and other strategically selected victims in Asia and beyond. Attribution to a specific state sponsor remains contested in some reporting, but the operation is widely treated as an advanced persistent threat.
DarkHotel malware has been observed using keylogging to capture user input and collect sensitive information from infected hosts. It also performs host and network reconnaissance, including gathering the victim system’s IP address and network adapter information. Samples have used RC4 to decrypt strings and imports at runtime, and have employed just-in-time decryption of strings as an anti-analysis measure intended to hinder sandbox detection and static inspection. Reporting also notes reuse of the ImprovedReflectiveDllInjection library, indicating support for in-memory loading or injection tradecraft within the broader toolset.
Operationally, DarkHotel has been associated with delivery through spoofed software installers, especially fake Flash Player updates served from compromised infrastructure or watering-hole style compromises. Campaigns using this approach selectively profiled visitors and only exposed payloads to systems meeting specific conditions, reflecting a targeted infection model rather than indiscriminate mass distribution. DarkHotel has also been referenced in connection with related malware such as Asruex, which has been described as linked to the same spyware ecosystem.
Overall, DarkHotel is best characterized as a Windows spyware and backdoor platform used in targeted espionage operations, combining credential and activity collection with reconnaissance and defense-evasion techniques.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
An example is the quick adoption by DarkHotel of a Flash zero-day found in the reckless full release of the HackingTeam trove [1].
8 distinct techniques documented for this family, organized by ATT&CK tactic.
IoCs include services such as mrxcls service, WinMI32 service, HP003044 service, NetBIOS2010 service, pnppci service, ethio service, ntdos505 service.
"...used tasklist to enumerate processes..."; "...used the ps command to list processes..."; "...calling CreateToolhelp32Snapshot... to enumerate the running processes..."
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
They check for the existence of specific files, windows registry entries, and other signs ... For example, this script looks for the existence of an actual file “winver32.exe” in the very specific $docsandsettings\\$subkey\\Application Data\\winver32.exe path.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as one of the notable advanced malware/toolsets frequently analyzed in earlier public research.
Named malware family/toolset cited as one of several that reused the ImprovedReflectiveDllInjection open-source library.
DarkHotel is described as a malware/toolset associated with spoofed Flash Player installers, backdoors, information stealing, hardcoded multi-domain C2 configuration, and targeted-yet-broad victimization. The article compares the KCNA-served malware to DarkHotel based on social engineering, data collection, network configuration, and infection behavior.
Malware with keylogger use/capability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.