logo

DarkHotel__2021__New_DarkHotel_APT_attack_chain_identified_Zscaler.pdf

ID: 419ea921-b5df-4431-a872-e8280fddbd86

STIX ID: report--419ea921-b5df-4431-a872-e8280fddbd86

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2021-12-21

Last Modified Date: 2021-12-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Executive summary: Zscaler ThreatLabz identified a previously undocumented DarkHotel APT attack chain (Nov 2021) that leverages a multi-layered DOCX/RTF with embedded OLE objects to drop and execute a scriptlet (googleofficechk.sct), which installs qq3104.exe and qq2688.exe, creates a persistent Windows service that runs encoded PowerShell to load an in-memory .NET downloader, and communicates with active C2 domains; the report provides technical analysis, IOCs (MD5, C2 domains/URLs, file and registry artifacts), and evidence of related phishing domains used to harvest cryptocurrency wallet credentials.