Trellix researchers recently detailed a spear-phishing campaign conducted against numerous luxury hotels in Macau, China, including the Grand Coloane Resort and Wynn Palace. Over seventeen hotel chains were targeted and the campaign was highly active until conferences were postponed or cancelled due to new Covid19 restrictions mandated for the region on January 18, 2022. The attacks were attributed with moderate confidence by Trellix researchers to the South Korean advanced persistent threat group (APT) DarkHotel based on similarities in malicious documents, dropped file system artifacts, attack chain, as well as Command-and-Control (C2) commands.
The spear-phishing attacks used malicious documents that requested the enablement of macros, which lead to an attack chain involving scheduled tasks for persistence, malicious vbs and PowerShell commands, and the dropping of additional malware to advance the attack chain and set up further data exfiltration and C2 activity.