Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Karkadann

Also known as: Piwiks

Description

Karkadann is a threat actor that has been active since at least October 2020, targeting government bodies and news outlets in the Middle East. They have been involved in watering hole attacks, compromising high-profile websites to inject malicious JavaScript code. The group has been linked to another commercial spyware company called Candiru, suggesting they may utilize multiple spyware technologies. There are similarities in the infrastructure and tactics used by Karkadann in their campaigns.

AI Analysis

· 1 week ago

Executive Summary

Karkadann, also known as Piwiks, is a threat actor active since October 2020. They primarily target government bodies and news outlets in the Middle East through watering hole attacks, compromising websites to inject malicious JavaScript. Associated with the commercial spyware company Candiru, Karkadann likely leverages similar spyware technologies. Their activities suggest they are part of a larger cyber espionage operation targeting sensitive sectors.

Goals & Targeting

Karkadann's strategic objectives appear to center around espionage and disrupting operations within Middle Eastern government bodies and news outlets. Their targeting profile reflects a focus on sectors that hold significant political and informational value in the region, likely aiming to gather sensitive data or disrupt public perception through compromised communications.

Enhanced Description

Karkadann is a cyber threat actor that first emerged in October 2020 and has been linked to attacks on government bodies and news organizations in the Middle East. The group's primary method involves watering hole attacks, where they compromise high-profile websites to inject malicious JavaScript code into their pages. This technique allows them to deliver payloads to unsuspecting visitors. Karkadann’s activities are notable for their potential ties to commercial spyware operations, particularly to the company Candiru. The overlap in infrastructure and tactics suggests that Karkadann may utilize similar spyware technologies or tools developed by Candiru. These campaigns demonstrate a focus on long-term access and intelligence gathering, aligning with the goals of an advanced persistent threat (APT) group.

Key Capabilities

  • Watering hole attacks
  • JavaScript-based malware injection
  • Spyware deployment (linked to Candiru)

MITRE ATT&CK Tactics

Lateral movement
Exfiltration
Defense evasion

ATT&CK Techniques

T1070.003
T1059.001
T1066.004

Software / Tooling

Custom JavaScript malware
Candiru's spyware tools

Campaigns & Victims

Karkadann’s campaigns have demonstrated a focus on persistent access and long-term infrastructure development. Their targeting of high-profile websites suggests an interest in wide-reaching impact. Campaigns are characterized by their use of malicious scripts injected into legitimate web properties, enabling compromise of site visitors. The group's operational tempo appears methodical, with a focus on maintaining persistence rather than rapidattack chains.

IOC Patterns

  • Compromised websites with injected JavaScript code
  • Watering hole attacks targeting government and media sectors
  • Malicious scripts delivered via legitimate web properties

Recommended Actions

  • Regularly monitor and secure high-profile websites for unauthorized JavaScript injections
  • Implement strict access controls and monitoring for web-based assets
  • Enhance endpoint detection capabilities to identify and block malicious scripts
  • Conduct regular phishing awareness training for employees, particularly in targeted sectors

Suggested Tags

APT
cyber espionage
Middle East
government targeting

Confidence Assessment

Confidence is moderate in Karkadann's activities due to their limited public reporting. While their association with Candiru and specific TTPs provide valuable context, gaps remain regarding their precise motivations and full range of capabilities.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
Government Targeting
APT
cyber espionage
Middle East
government targeting

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.