Also known as: Piwiks
Karkadann is a threat actor that has been active since at least October 2020, targeting government bodies and news outlets in the Middle East. They have been involved in watering hole attacks, compromising high-profile websites to inject malicious JavaScript code. The group has been linked to another commercial spyware company called Candiru, suggesting they may utilize multiple spyware technologies. There are similarities in the infrastructure and tactics used by Karkadann in their campaigns.
Executive Summary
Karkadann, also known as Piwiks, is a threat actor active since October 2020. They primarily target government bodies and news outlets in the Middle East through watering hole attacks, compromising websites to inject malicious JavaScript. Associated with the commercial spyware company Candiru, Karkadann likely leverages similar spyware technologies. Their activities suggest they are part of a larger cyber espionage operation targeting sensitive sectors.
Goals & Targeting
Karkadann's strategic objectives appear to center around espionage and disrupting operations within Middle Eastern government bodies and news outlets. Their targeting profile reflects a focus on sectors that hold significant political and informational value in the region, likely aiming to gather sensitive data or disrupt public perception through compromised communications.
Enhanced Description
Karkadann is a cyber threat actor that first emerged in October 2020 and has been linked to attacks on government bodies and news organizations in the Middle East. The group's primary method involves watering hole attacks, where they compromise high-profile websites to inject malicious JavaScript code into their pages. This technique allows them to deliver payloads to unsuspecting visitors. Karkadann’s activities are notable for their potential ties to commercial spyware operations, particularly to the company Candiru. The overlap in infrastructure and tactics suggests that Karkadann may utilize similar spyware technologies or tools developed by Candiru. These campaigns demonstrate a focus on long-term access and intelligence gathering, aligning with the goals of an advanced persistent threat (APT) group.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Karkadann’s campaigns have demonstrated a focus on persistent access and long-term infrastructure development. Their targeting of high-profile websites suggests an interest in wide-reaching impact. Campaigns are characterized by their use of malicious scripts injected into legitimate web properties, enabling compromise of site visitors. The group's operational tempo appears methodical, with a focus on maintaining persistence rather than rapidattack chains.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence is moderate in Karkadann's activities due to their limited public reporting. While their association with Candiru and specific TTPs provide valuable context, gaps remain regarding their precise motivations and full range of capabilities.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics