Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Dark Caracal

Also known as: G0070

Description

Dark Caracal is threat group that has been attributed to the Lebanese General Directorate of General Security (GDGS) and has operated since at least 2012. (Citation: Lookout Dark Caracal Jan 2018)

AI Analysis

· 2 weeks ago

Executive Summary

Dark Caracal is an espionage-focused threat group linked to the Lebanese General Directorate of General Security (GDGS) and active since at least 2012. The group specializes in mobile and Windows malware to harvest credentials, conduct surveillance, and exfiltrate sensitive data from government, telecom, and civil‑society targets. Their operations demonstrate a moderate‑to‑high level of sophistication and a clear state‑aligned intelligence motive.

Goals & Targeting

Dark Caracal’s strategic objective is to collect intelligence that supports Lebanese national security and diplomatic agendas. The group prioritizes sectors that hold politically sensitive information—such as foreign ministries, embassies, telecom operators, and human‑rights NGOs—particularly in countries where Lebanon seeks geopolitical influence (e.g., Gulf states, Europe, and the United States). Their typical victims are individuals with privileged access to communications, policy documents, or network infrastructure, enabling the actors to harvest credentials, monitor communications, and map organizational structures for downstream exploitation.

Enhanced Description

Dark Caracal, also known by the designation G0070, has been attributed to the Lebanese General Directorate of General Security (GDGS). Open‑source investigations trace its activity back to 2012, making it one of the longer‑running APT groups in the Middle East. The group’s primary motivation is espionage, and its campaigns have consistently targeted diplomatic, governmental, telecommunications, and civil‑society organizations across multiple regions. The group’s toolkit centers on custom Android and Windows payloads, most notably the "Pallas" RAT family, which provides remote command and control, credential harvesting, and device surveillance capabilities. In addition to mobile implants, Dark Caracal has employed PowerShell scripts, malicious Microsoft Office documents with embedded macros, and legitimate remote‑access utilities to gain footholds and move laterally within victim networks. Their operational tradecraft includes the use of compromised legitimate domains for C2, fast‑flux hosting, and multi‑stage payload delivery to evade detection. Dark Caracal’s campaigns often begin with spear‑phishing emails that contain weaponized attachments or links to malicious landing pages. Once a victim executes the payload, the malware establishes encrypted communications over HTTPS or DNS, allowing the actors to exfiltrate data and receive additional modules. The group demonstrates a strong focus on stealth, employing code obfuscation, packing, and legitimate system utilities to blend in with normal traffic. Although public reporting of Dark Caracal has decreased after 2018, threat‑intel feeds continue to observe remnants of their infrastructure and occasional re‑use of their toolset by related actors. This persistence suggests a sustained intelligence‑gathering effort aligned with Lebanese state interests.

Key Capabilities

  • Development of custom Android and Windows RATs (e.g., Pallas)
  • Spear‑phishing with malicious Office documents and links
  • PowerShell and JavaScript based execution frameworks
  • Encrypted C2 channels over HTTPS, DNS, and web services
  • Credential harvesting and keylogging on mobile devices
  • Use of legitimate remote‑access tools for lateral movement
  • Code obfuscation, packing, and anti‑analysis techniques

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Command and Control

ATT&CK Techniques

T1566.001
T1566.002
T1059.001
T1059.003
T1059.007
T1059.001
T1055
T1105
T1027
T1071.001
T1071.004
T1041
T1090
T1087
T1069.001
T1547.001
T1543.003
T1456
T1476

Software / Tooling

Pallas RAT
Custom Android malware (Dark Caracal mobile implant)
PowerShell scripts
Mimikatz (used for credential dumping)
Cobalt Strike (observed in later stages)
Valid Accounts abuse

Campaigns & Victims

Dark Caracal’s campaigns typically follow a multi‑stage approach: initial spear‑phishing, deployment of a mobile or Windows implant, establishment of encrypted C2, and staged credential theft followed by data exfiltration. Operational tempo has been moderate, with bursts of activity aligned to regional political events (e.g., elections, diplomatic negotiations). Notable operations include the 2015‑2017 targeting of Lebanese diaspora NGOs and the 2016 compromise of telecom providers in the Gulf, where the group harvested subscriber data and internal communications. While public disclosures have waned, threat‑intel monitoring still detects reused infrastructure and occasional re‑branding of their malware families.

IOC Patterns

  • Spear‑phishing emails with macro‑laden Word or Excel attachments
  • Malicious links to credential‑harvesting landing pages hosted on compromised domains
  • C2 traffic over HTTPS on non‑standard ports
  • DNS tunneling for data exfiltration
  • Use of bullet‑proof hosting services for staging payloads
  • Obfuscated PowerShell scripts embedded in Office documents

Recommended Actions

  • Implement strict email attachment scanning and macro blocking policies.
  • Deploy endpoint detection and response (EDR) solutions with mobile device monitoring capabilities.
  • Enforce multi‑factor authentication for privileged accounts and VPN access.
  • Monitor network traffic for anomalous HTTPS/DNS patterns and fast‑flux domains.
  • Conduct regular threat‑intel briefings on Dark Caracal IOCs and update blocklists.
  • Perform periodic credential hygiene audits and enforce least‑privilege principles.
  • Isolate and segment high‑value systems, especially those handling diplomatic or telecom data.

Suggested Tags

APT
Espionage
Lebanon
Mobile Malware
State‑Sponsored
Government
Telecom
Human Rights

Confidence Assessment

Confidence in the core attribution to the Lebanese GDGS and the group’s espionage motive is high, based on multiple independent security reports and technical analyses. However, gaps remain regarding the full extent of their current operational activity, specific targeting timelines, and any evolution of their toolset post‑2018. Continuous monitoring of emerging IOCs and threat‑intel feeds is recommended to fill these gaps.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Lookout Dark Caracal Jan 2018 — Blaich, A., et al. (2018, January 18). Dark Caracal: Cyber-espionage at a Global Scale. Retrieved April 11, 2018.

Intel Summary

12

Techniques

3

Tools

0

Campaigns

0

IOCs

0

Observed Data

7

Tactics

Tags

APT

Details

MITRE ID
G0070
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Country of Origin
L
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--8a831aaa-f3e0-47a3-bed8-a9ced744dd12
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.