DarkHotel__2021__New_DarkHotel_APT_attack_chain_identified_Zscaler.pdf
ID: 419ea921-b5df-4431-a872-e8280fddbd86
STIX ID: report--419ea921-b5df-4431-a872-e8280fddbd86
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2021-12-21
Last Modified Date: 2021-12-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Executive summary: Zscaler ThreatLabz identified a previously undocumented DarkHotel APT attack chain (Nov 2021) that leverages a multi-layered DOCX/RTF with embedded OLE objects to drop and execute a scriptlet (googleofficechk.sct), which installs qq3104.exe and qq2688.exe, creates a persistent Windows service that runs encoded PowerShell to load an in-memory .NET downloader, and communicates with active C2 domains; the report provides technical analysis, IOCs (MD5, C2 domains/URLs, file and registry artifacts), and evidence of related phishing domains used to harvest cryptocurrency wallet credentials.
