Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Dark Hotel targets execs in hotels – industry views

by The Gurus
June 12, 2020
in Opinions & Analysis
Share on FacebookShare on Twitter

Following four years worth of research, research emerged from Kaspersky Lab of an espionage campaign that stole sensitive data from selected corporate executives travelling abroad.
 
Named “Darkhotel”, it comprised both targeted attacks and botnet style operations and focused on C-level executives by hitting targets while they are staying in luxury hotels. It found that once connected to a hotel’s WiFi network, the attacker tricks the user into downloading a backdoor masquerading as legitimate software, infecting the device with the “Darkhotel” spying software.
 
Once on a system, the backdoor has been, and may be used, to further download more advanced stealing tools: a digitally-signed advanced keylogger, the Trojan ‘Karba’ and an information-stealing module. These tools collect data about the system and the anti-malware software installed on it, steals all keystrokes, and hunt for cached passwords in Firefox, Chrome and Internet Explorer.
 
It also looks for Gmail Notifier, Twitter, Facebook, Yahoo! and Google login credentials, as well as other private information. Is this a new threat, or should people be more careful about what they are connecting to outside of the office?
 
 
KurtBaumgartner.JPG
Kurt Baumgartner, principal security researcher at Kaspersky Lab
 
“This threat actor has operational competence, mathematical and crypto-analytical offensive capabilities, and other resources that are sufficient to abuse trusted commercial networks and target specific victim categories with strategic precision.
 
“The mix of both targeted and indiscriminate attacks is becoming more and more common in the APT scene, where targeted attacks are used to compromise high profile victims, and botnet-style operations are used for mass surveillance or performing other tasks such as DDoSing hostile parties or simply upgrading interesting victims to more sophisticated espionage tools.”
 
 
Chris Boyd, Malware Intelligence Analyst at Malwarebytes
 
“The Dark Hotel Malware is a good reminder that any hotel WiFi network is potentially unsafe, and should be treated with caution. Travellers should take the time to research ISPs in the regions they’re visiting and invest in WiFi datasticks.
 
“Remembering to make use of the corporate VPN wouldn’t go amiss, although anybody conducting business while on the road should be doing this anyway. If the primary threat is pop-ups asking potential victims to install fake Flash files, then perhaps the security teams for those companies should be spending more time educating their CEOs on the dangers of basic social engineering.”
 

 Ian Pratt, co-founder at Bromium
 
“Even a VPN is unable to help protect against many of these attacks. Most WiFi networks require you to successfully sign-in to a captive portal page before they will allow you external access. In many cases it is the sign-in page itself that is malicious, and by the time the user has entered their surname and room number they will have been delivered an exploit tailored to their m
achine and compromised. Bringing a VPN up at this point plays directly into the attackers hands, bringing the infection onto the enterprise network.
 
I don’t think execs are getting enough security education, and they are typically some of the worst at following operational security advice they have been given. Worse, there are many examples of exec’s using their political clout to ask for IT restrictions that other employees face to be removed for themselves, without understanding the consequences. Everyone needs to understand the risk and the appropriate mitigations.”
 
 
 Mark James, security specialist at ESET
 
“Often security procedures do not extend to executives who have the authority to say ‘no’ as it often causes inconvenience. It is imperative that these procedures are adhered to and even more so for execs as they have the most sought after data.
 
“Most companies have some kind of security education, but I am sure if you were to hold a poll most of those trainers would tell you the company executives are very rarely in the audience – yet they are the very targets that have the data worth stealing. Good user education is the very foundation of protecting your data – from the ‘newbie’ right through to the CEO – no one is above being taught how to protect you or your company’s data.”
 

Amichai Shulman, CTO Imperva
 
“The WiFi related attacks described in the report are actually more related to hotel internet access than anything else. When connecting to the internet from a hotel room (either wireless or wired) guests are usually first served pages from a hotel portal. These pages were infected by the attackers to deliver malware disguised as common software (Adobe reader, Flash player, etc.).
 
“Sophistication in this case is not attributed to the infection of the guest, but actually to being able to remain under the hotel IT security personnel radar for a long time (presumably, according to the report) and be able to target specific guests rather than a widespread infection. Hotel room internet connections have been considered generally insecure for many years, indicating that such attacks are not rare.”
 

 
Richard Cassidy, senior solutions architect at Alert Logic
 
“It is feasible to assume that the ‘internet portals’ at the affected locations are being compromised and in many cases, this portal may allow the hacker cell access to backend systems to gain more data on the users they need to target and in other cases to infect that portal with code to facilitate the attack and then delete all traces when successful.
 
“In this respect we are seeing a very sophisticated attack on the target networks by this cell, who have put a great deal of thought into what information they want, who they are targeting and how to write malware that provides the best chance of getting what they’re after.”
 
TK Keanini, CTO at Lancope
 
“This is a product of the fact that the business traveller today must remain connected to their business and that adversaries have found physical and logical ways to access your devices while you are travelling.
 
“It is not just the executives, but all International travelers must be aware of these threats both physical and logical. They likelihood of these events happening are even higher
than any disease one might contract and we have preventative programs around those.”
 

Paul Pratley, head of investigations and incident response at MWR Infosecurity
 
“Attacks over WiFi are certainly becoming more common, however targeted attacks aimed at executives really only happen where the attacker knows the individual is going to be in a certain place at a particular time and of course, known to be connecting to the WiFi network. This may be the case for hotels that are frequented by a particular company, that for instance, is located near to a company HQ and have a standing agreement.
 
“Execs need a lot more education on the specific risks that are present in the use of untrusted networks of any type and be made aware of what it looks like when they are being tricked into making bad security decisions. Far too many IT security teams trust that their execs will know when something isn’t quite right, rather than showing them the signs of an attempted attack.”
 

Tags: attackExecutiveHotelKeyloggerTargetedWiFi
ShareTweet
Previous Post

China Breach Delivers Problems for US Postal Service

Next Post

SaaS requires a different Logic

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol