logo

New DarkHotel APT attack chain identified

ID: 5ff2fd45-d785-5967-ba9b-f735d4320999

STIX ID: report--5ff2fd45-d785-5967-ba9b-f735d4320999

Feed Name: Zscaler Security Research Blog

Threat Score
85/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This November 2021 report documents a DarkHotel APT campaign using a multi-layer malicious Office document (MD5 89ec1f32...) that drops a scriptlet (googleofficechk.sct) to install and execute two binaries (qq3104.exe, qq2688.exe). The chain includes PEB spoofing, UAC bypass, service-based persistence launching obfuscated PowerShell which loads an in-memory .NET downloader, and communicates with C2 domains (signing-config.com, svcstat.com, relay-server.com); the report includes C2/IP/domain analysis and IOCs, plus phishing domains targeting cryptocurrency wallets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.