Cookies on the BBC website
We use cookies to ensure that we give you the best experience on our website.
We also use cookies to ensure we show you advertising that is relevant to you.
If you continue without changing your settings, we'll assume that you are happy to receive all cookies on the BBC website. However, if you would like to, you can change your cookie settings
at any time.
Accessibility links
IN ASSOCIATION WITH
11 November 2014
Last updated at
13:20 GMT
Security researchers believe DarkHotel has targeted hotel guests for seven years
The malware was attached to legitimate updates for Adobe Flash and other software
The majority of the detected attacks targeted visitors to Japanese hotels
Der Spiegel published allegations about GCHQ's hotel spying efforts as part of its coverage of whistleblower Edward Snowden's release of leaked documents
DarkHotel hackers targets company bosses in hotel rooms
By Leo Kelion Technology desk editor
Continue reading the main story
Related Stories
Companies are being warned about ongoing hack attacks that target hi-tech entrepreneurs and other corporate executives in their hotel rooms.
The campaign has been dubbed DarkHotel and is believed to single out specific senior staff when they log in to the net via wi-fi or an Ethernet cable.
The technique puts data at risk even if the employees are using encryption.
The attacks began in 2007, according to research firm Kaspersky Lab.
"The fact that most of the time the victims are top executives indicates the attackers have knowledge of their victims' whereabouts, including name and place of stay," said the
Russian security company.
"This paints a dark, dangerous web in which unsuspecting travellers can easily fall."
The firm's research indicates the majority of the attacks to date have taken place in Japan but that visitors to hotels in Taiwan, mainland China, Hong Kong, Russia, South Korea, India, Indonesia, Germany, the US and Ireland have also been targeted.
It said that the effort was "well-resourced", but it was unclear who was responsible.
One independent expert said the hacks should not come as too much of a shock.
"It's unsurprising given the high value of the targets," commented Dr Ian Brown, from the Oxford Internet Institute.
"This is perhaps a wake-up call to big company CEOs who weren't already aware that this kind of thing was going on."
Copied certificates
The scheme works by requesting that the targeted user installs an update to a popular software package shortly after they connect to the net.
Examples include new versions of Adobe Flash, Google Toolbar and Windows Messenger.
The installation files include legitimate software, but with the DarkHotel code added on.
To prevent the malware being detected, the hackers use certificates - the equivalent of a digital password, used under normal circumstances to confirm software is trustworthy.
They were able to do this by taking copies of valid certificates that were protected by relatively weak levels of encryption, which they were capable of breaking.
Kaspersky said that examples of spoofed certificates that its researchers had found included ones issued by Deutsche Telekom, Cybertrust and Digisign.
The result is that the hackers can then employ other types of malware.
These are said to include:
- Keyloggers - used to record and transmit a user's individual keyboard and mouse presses in order to monitor their activity
- Information stealers - used to copy data off the computer's hard drive, including passwords stored by internet browsers, and the logins for cloud services including Twitter, Facebook, Mail.ru and Google
- Trojans - used to scan a system's contents, including information about the anti-virus software it has installed. The findings are then uploaded to the hackers' computer servers
- Droppers - software that installs further viruses on the system
- Selective infectors - code that spreads the malware to other computer equipment via either a USB connection or shared removable storage. These targets appeared to be "systematically vetted" before being infected
- Small downloaders - files designed to contact the hackers' server after 180 days. The belief is that this is intended to let them take back control if some of the other malware is detected and removed
The researchers said workers for electronics manufacturers, pharmaceutical companies, cosmetic makers, car designers, the military and non-governmental organisations had all been targeted.
They added that the employees had probably been identified by the last name and room number they were required to enter in order to access the internet, inferring that they must have had a separate way to determine their targets' travel dates, assigned room numbers and other details.
"The attackers were also very careful to immediately delete all traces of their tools as soon as an attack was carried out successfully," they added.
Royal Concierge
Dr Brown noted that GCHQ was believed to operate a separate but similar system of its own.
Last year Der Spiegel
published allegations
that the UK spy agency used a system called Royal Concierge to track foreign diplomats' reservations at at least 350 upmarket hotels around the world. Once a room was identified, it reported, agents would be deployed to monitor the target's communications.
"It's not surprising that other countries would be wanting to do this," Dr Brown commented.
He added that one way to avoid the risk would be to ensure top-level employees were equipped with personal mobile hotspots, which use a 3G or 4G cellular data connection, rather than hotels' own internet equipment.
Related Stories
- 06 NOVEMBER 2014, TECHNOLOGY
- 29 OCTOBER 2014, TECHNOLOGY
- 28 JANUARY 2014, TECHNOLOGY
From other news sites
-
CNET Asia 'Darkhotel' hack targets executives using hotel Internet 37 hrs ago
-
Techworld.com Darkhotel APT hackers campaign 'followed' global CEOs using hotel networks 37 hrs ago
-
Guardian.co.uk Hackers used luxury hotel Wi-Fi to steal business executive's data, researchers say 38 hrs ago
-
Reuters UK Execs in Asian luxury hotels fall prey to cyber-espionage - study 40 hrs ago
-
International Business Times UK DarkHotel: Cyber-Criminals Use Hotel WiFi to Attack High Value Targets - Are You Safe? 40 hrs ago
- About these results
Related Internet links
The BBC is not responsible for the content of external Internet sites
More Technology stories
RSS-
Assassin's Creed glitches criticised
Widespread glitches in French Revolution-set Assassin's Creed: Unity have put its publisher Ubisoft under pressure. -
Hackers exploit touch payment tech
-
S&P gives Twitter debt 'junk' status
Top Stories
Features & Analysis
-
Locked up
The children who are kept in cages
-
Elvis Romano
Watch
School teacher who likes to rock 'n' roll the Romany way
-
'They banned colours'
School is not the same under Islamic State rule in Iraq
-
News quiz
What brought pop stars' duet to a premature end?
Most Popular
Shared
Read
- 1: Comet lander: Future of Philae probe 'uncertain'
- 2: Jagger 'upset' by court disclosure
- 3: M25 collapses following roadworks
- 4: 'Tiger' search resumes near Paris
- 5: The man who seemed not to notice danger
- 6: Polish woman 'returns from the dead'
- 7: Russia sanctions 'undermine trade'
- 8: 'Time for risks' with comet lander
- 9: The disabled children locked up in cages
- 10: Iraq troops 'push IS from oil town'
Video/Audio
- 2: Footage shows lorry motorway U-turn Watch
- 3: How does comet compare to your city? Watch
- 4: 'Revenge porn' victim faces arrest Watch
- 5: Helicopter hunt for 'tiger' on the loose Watch
- 6: One-minute World News Watch
- 7: 'Fantastic, fantastic, it's landed' Watch
- 9: How to deal with jihadi homecomings? Watch
- 10: Photos of Earth's beauty from space Watch
In association with
BBC Future
Movie lessons on life in space
Don’t trust the computers – or aliens Read more...Programmes
-
The Travel Show
Watch
Australian gold rush - from prospectors finding ounces to a super pit producing tonnesIn association with
Connect with BBC News
BBC links
This page is best viewed in an up-to-date web browser with style sheets (CSS) enabled. While you will be able to view the content of this page in your current browser, you will not be able to get the full visual experience. Please consider upgrading your browser software or enabling style sheets (CSS) if you are able to do so.
End of panel.
Back to top of panelClose Panel