Darkhotel: Following the public leak of files of Hacking Team, a company that became known for selling «νόμιμου» spyware to certain government agencies and law‑enforcement authorities, several digital espionage groups have started using, for their own malicious purposes, tools that Hacking Team supplied to its customers, to carry out attacks. 
These include several exploits targeting Adobe Flash Player and the Windows operating system. At least one of them has been used by the “Darkhotel” group, a powerful digital espionage actor.
Kaspersky Lab has discovered that the elite digital espionage group «Darkhotel», which was revealed by the company's experts in 2014 and is renowned for infiltrating Wi‑Fi networks of luxury hotels targeting selected corporate executives, uses a zero‑day vulnerability from the Hacking Team collection since early July, immediately after the infamous Hacking Team file leak on July 5.
Since it is not known as a client of Hacking Team, the Darkhotel group appears to have taken possession of the files as soon as they were leaked publicly.
This is not the only zero‑day vulnerability used by the group. Kaspersky Lab estimates that in recent years it may have encountered six or even more zero‑day exploit programs targeting the Adobe Flash Player, a fact that clearly shows that the entity is investing significant amounts to strengthen its «arsenal» its.
In 2015, the Darkhotel group expanded its geographical operations worldwide, and it continues to attack targets in North and South Korea, Russia, Japan, Bangladesh, Thailand, India, Mozambique, and Germany.
Side assistance from Hacking Team
The security researchers at Kaspersky Lab have recorded new techniques and activities of the Darkhotel group, a well-known APT attack entity that has been operating for almost eight years. In attacks from 2014 and earlier, the group used stolen code-signing certificates and adopted unusual methods, such as compromising hotel Wi-Fi networks, aiming to place espionage tools on the targets' systems.
In 2015, many of these techniques and activities have been maintained, but Kaspersky Lab has also discovered new variants of malicious executable files, continuous use of stolen certificates, relentless use of social engineering techniques, and the use of zero‑day vulnerability programs from the Hacking Team.
- Continuous use of stolen certificates: The Darkhotel group appears to maintain a stock of stolen certificates and uses downloaders and backdoors that have the corresponding signatures, in order to compromise the targeted system. The certificates that have been revoked most recently include those of Xuchang Hongguang Technology Co. Ltd., a company whose certificates were used in previous attacks by the threat actor.
- Persistent lateral attacks: The APT attack Darkhotel is indeed persistent. It tries to attack the target via lateral paths and if it fails, it returns a few months later, using roughly the same social engineering techniques.
- Exploitation of zero-day vulnerabilities of the Hacking Team: The compromised website, tisone360.com, contains a series of backdoors and exploits. The most interesting of these is the Hacking Team Flash zero-day vulnerability.
"The Darkhotel group is back with another exploit , hosted on a compromised website. This time, it appears to have come from the Hacking Team leaks. The group previously used a different Flash exploit, which we reported as a zero-day vulnerability to Adobe in January 2014.
" Darkhotel appears to have been in possession of many zero-day and half - day exploits in recent years, and may have amassed even more to execute targeted attacks against high-ranking executives. From previous attacks, we know that the Darkhotel group spies on CEOs, executive vice presidents, sales and marketing managers, and top R&D executives," said Kurt Baumgartner, Principal Security Researcher at Kaspersky Lab.
Since 2014, the group has improved its defensive techniques, expanding – for example – the list of anti-detection technologies. The 2015 version of the Darkhotel downloader has been designed to detect the antivirus technologies of 27 solution providers, aiming to bypass them.
More information is available on the Securelist.com.
General information on mitigating APT attacks is available in a special Kaspersky post
