Volatile Cedar
MITRE ATT&CK: G0123 View on attack.mitre.org
Aliases: Lebanese Cedar, DeftTorero, Volatile Cedar
- First seen
- 2012-01-01 00:00:00
- Origin
- LB
- Primary motivation
- ideology
- Sophistication
- intermediate
- Resource level
- team
- Actor type
- nation-state
- Related IoCs
- 3 (3 malicious)
- Last IoC activity
- 2025-10-30 13:32:38
- Profile updated
- 2026-07-07 11:51:54
Targeted industries: government-and-public-sector media-and-entertainment technology-and-telecommunications
Context
Volatile Cedar is a Lebanese threat group that has targeted individuals, companies, and institutions worldwide. Volatile Cedar has been operating since 2012 and is motivated by political and ideological interests.
Recent IoC activity
3 malicious indicators in Maltiverse are attributed to Volatile Cedar (G0123). The 3 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | ploreredotntxe.net | 2025-10-30 | 1 |
| hostname | tadobeflasehplayerg.net | 2025-09-16 | 1 |
| hostname | edotntexrplore.info | 2025-08-07 | 1 |
Detection coverage
- 1 YARA rules
- 140 Sigma rules
Malware & tools used
- Vulnerability Scanning (attack-pattern)
- Wordlist Scanning (attack-pattern)
- Web Shell (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
- Explosive (malware)
- Caterpillar WebShell (malware)
Reports & references
- blog.checkpoint.com — Volatilecedar (report)
- blog.checkpoint.com — New Data Volatile Cedar (report)
- Kaspersky — 69421 (report)
- clearskysec.com — Lebanese Cedar Apt (report)
- media.kasperskycontenthub.com — Volatile Cedar Technical Report (report)
- Kaspersky — 107610 (report)
- MITRE ATT&CK — G0123 (report)