Dark Caracal

MITRE ATT&CK: G0070 View on attack.mitre.org

Aliases: Dark Caracal

First seen
2012-01-01 00:00:00
Origin
LB
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Related IoCs
1 (1 malicious)
Last IoC activity
2026-05-21 10:53:34
Profile updated
2026-07-07 11:54:36

Targeted industries: government-and-public-sector media-and-entertainment energy-and-utilities technology-and-telecommunications defense-and-aerospace

Targeted regions: country_code:lb country_code:us country_code:de country_code:tr country_code:sa

Context

Dark Caracal is threat group that has been attributed to the Lebanese General Directorate of General Security (GDGS) and has operated since at least 2012.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to Dark Caracal (G0070). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample 20fd6d2c4058ff01add0e8e260540d98fc6af8c7a6db8c6b1038497bdedd028d 2026-05-21 1

Detection coverage

  • 3 YARA rules
  • 168 Sigma rules

Malware & tools used

  • Encrypted/Encoded File (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Web Protocols (attack-pattern)
  • Malicious File (attack-pattern)
  • Software Packing (attack-pattern)
  • Compiled HTML File (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Spearphishing via Service (attack-pattern)
  • Data from Local System (attack-pattern)
  • Screen Capture (attack-pattern)
  • Web Protocols (attack-pattern)
  • Bandook (malware)
  • FinFisher (malware)
  • CrossRAT (malware)
  • Pallas (malware)

Reports & references

  • info.lookout.com — Lookout Dark Caracal Srr 20180118 Us V.1.0 (report)
  • research.checkpoint.com — Bandook Signed Delivered (report)
  • MITRE ATT&CK — G0070 (report)

External references