Dark Caracal
MITRE ATT&CK: G0070 View on attack.mitre.org
Aliases: Dark Caracal
- First seen
- 2012-01-01 00:00:00
- Origin
- LB
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-05-21 10:53:34
- Profile updated
- 2026-07-07 11:54:36
Targeted industries: government-and-public-sector media-and-entertainment energy-and-utilities technology-and-telecommunications defense-and-aerospace
Targeted regions: country_code:lb country_code:us country_code:de country_code:tr country_code:sa
Context
Dark Caracal is threat group that has been attributed to the Lebanese General Directorate of General Security (GDGS) and has operated since at least 2012.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to Dark Caracal (G0070). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 20fd6d2c4058ff01add0e8e260540d98fc6af8c7a6db8c6b1038497bdedd028d | 2026-05-21 | 1 |
Detection coverage
- 3 YARA rules
- 168 Sigma rules
Malware & tools used
- Encrypted/Encoded File (attack-pattern)
- Windows Command Shell (attack-pattern)
- Web Protocols (attack-pattern)
- Malicious File (attack-pattern)
- Software Packing (attack-pattern)
- Compiled HTML File (attack-pattern)
- Drive-by Compromise (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Spearphishing via Service (attack-pattern)
- Data from Local System (attack-pattern)
- Screen Capture (attack-pattern)
- Web Protocols (attack-pattern)
- Bandook (malware)
- FinFisher (malware)
- CrossRAT (malware)
- Pallas (malware)
Reports & references
- info.lookout.com — Lookout Dark Caracal Srr 20180118 Us V.1.0 (report)
- research.checkpoint.com — Bandook Signed Delivered (report)
- MITRE ATT&CK — G0070 (report)