Dark Caracal

🔴 High
Also known as: Dark Caracal, G0070

Dark Caracal is threat group that has been attributed to the Lebanese General Directorate of General Security (GDGS) and has operated since at least 2012. Lookout Dark Caracal Jan 2018

🌍 Country Lebanon
Risk Level High
🧭 ATT&CK G0070

Introduction

Dark Caracal is threat group that has been attributed to the Lebanese General Directorate of General Security (GDGS) and has operated since at least 2012. Lookout Dark Caracal Jan 2018

Activities and Tactics

Country of Origin: 🏳️ Lebanon

Risk Level: High

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

ATT&CK technique IDs (denormalized)

Notable Indicators of Compromise (IOCs)

No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.

Malware and Tools

  • Dark DDoSeR
  • CrossRat
  • Pallas Bandook CrossRAT Infected Documents:

MITRE ATT&CK Software

Attribution and Evidence

Country of Origin: Lebanon Additional attribution information pending cataloguing.

References

[1] mitre-attack [3] Lookout Dark Caracal Jan 2018 Blaich, A., et al. (2018, January 18). Dark Caracal: Cyber-espionage at a Global Scale. Retrieved April 11, 2018.