New: 2026 Gartner® Market Guide for Adversarial Exposure Validation
Learn More
Cymulate named a Customers' Choice in 2025 Gartner® Peer Insights™
Learn More
New Research: The Security Tradeoffs Behind AI Tooling
Learn More
An Inside Look at the Technology Behind Cymulate
Learn More

New DarkHotel APT attack chain identified

December 20, 2021

This attack chain is attributed to the Dark Hotel APT group with a high level of confidence due to the below reasons: 1. The multi-layer malicious document which drops a scriptlet post-exploitation. 2. Filename of the dropped file system artifacts such as the scriptlet file - googleofficechk.sct 3. The command-and-control (C2) commands are the same as earlier payloads used by Dark Hotel. 4. Timestamps of the dropped payloads are around the same timeframe when previously documented Dark Hotel APT activity was observed.