Threat Actor Characterization
You’re viewing the read-only version.
Sign in for analyst tools (editors, promote draft, file/relations management, etc.)
Dark Caracal
ID: 57b88ca56ed4a3b2717e5c3132a5459861354
Cybercrime
State-Sponsored
Threat types: Spyware/Stealer, Surveillance, Intrusion
Progress: 35%
Completeness: 28%
Freshness: 50%
Operation zone: UNKNOWN
Aliases
Limited alias preview
No aliases registered.
Actor Network Graph
Open Network GraphMITRE ATT&CK®
confidence: medium
Dark Caracal is threat group that has been attributed to the Lebanese General Directorate of General Security (GDGS) and has operated since at least 2012. Ref: https://attack.mitre.org/groups/G0070/
| Technique | Technique name | Tactics | Evidence |
|---|---|---|---|
| T1027.002 | Software Packing | TA0005 |
|
| T1027.013 | Encrypted/Encoded File | TA0005 |
|
| T1059.003 | Windows Command Shell | TA0002 |
|
| T1071.001 | Web Protocols | TA0011 |
|
| T1204.002 | Malicious File | TA0002 |
|
| T1218.001 | Compiled HTML File | TA0005 |
|
| T1437.001 | Web Protocols | TA0037 |
|
| T1547.001 | Registry Run Keys / Startup Folder | TA0003 TA0004 |
|
| T1566.003 | Spearphishing via Service | TA0001 |
|
Executive brief
now
Saved successfully.
Hunting Playbook
now
Saved successfully.
IOC Appendix
now
Saved successfully.
OSINT Library
now
Saved successfully.