Also known as: G0070
Dark Caracal is threat group that has been attributed to the Lebanese General Directorate of General Security (GDGS) and has operated since at least 2012. (Citation: Lookout Dark Caracal Jan 2018)
Executive Summary
Dark Caracal is an espionage-focused threat group linked to the Lebanese General Directorate of General Security (GDGS) and active since at least 2012. The group specializes in mobile and Windows malware to harvest credentials, conduct surveillance, and exfiltrate sensitive data from government, telecom, and civil‑society targets. Their operations demonstrate a moderate‑to‑high level of sophistication and a clear state‑aligned intelligence motive.
Goals & Targeting
Dark Caracal’s strategic objective is to collect intelligence that supports Lebanese national security and diplomatic agendas. The group prioritizes sectors that hold politically sensitive information—such as foreign ministries, embassies, telecom operators, and human‑rights NGOs—particularly in countries where Lebanon seeks geopolitical influence (e.g., Gulf states, Europe, and the United States). Their typical victims are individuals with privileged access to communications, policy documents, or network infrastructure, enabling the actors to harvest credentials, monitor communications, and map organizational structures for downstream exploitation.
Enhanced Description
Dark Caracal, also known by the designation G0070, has been attributed to the Lebanese General Directorate of General Security (GDGS). Open‑source investigations trace its activity back to 2012, making it one of the longer‑running APT groups in the Middle East. The group’s primary motivation is espionage, and its campaigns have consistently targeted diplomatic, governmental, telecommunications, and civil‑society organizations across multiple regions. The group’s toolkit centers on custom Android and Windows payloads, most notably the "Pallas" RAT family, which provides remote command and control, credential harvesting, and device surveillance capabilities. In addition to mobile implants, Dark Caracal has employed PowerShell scripts, malicious Microsoft Office documents with embedded macros, and legitimate remote‑access utilities to gain footholds and move laterally within victim networks. Their operational tradecraft includes the use of compromised legitimate domains for C2, fast‑flux hosting, and multi‑stage payload delivery to evade detection. Dark Caracal’s campaigns often begin with spear‑phishing emails that contain weaponized attachments or links to malicious landing pages. Once a victim executes the payload, the malware establishes encrypted communications over HTTPS or DNS, allowing the actors to exfiltrate data and receive additional modules. The group demonstrates a strong focus on stealth, employing code obfuscation, packing, and legitimate system utilities to blend in with normal traffic. Although public reporting of Dark Caracal has decreased after 2018, threat‑intel feeds continue to observe remnants of their infrastructure and occasional re‑use of their toolset by related actors. This persistence suggests a sustained intelligence‑gathering effort aligned with Lebanese state interests.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Dark Caracal’s campaigns typically follow a multi‑stage approach: initial spear‑phishing, deployment of a mobile or Windows implant, establishment of encrypted C2, and staged credential theft followed by data exfiltration. Operational tempo has been moderate, with bursts of activity aligned to regional political events (e.g., elections, diplomatic negotiations). Notable operations include the 2015‑2017 targeting of Lebanese diaspora NGOs and the 2016 compromise of telecom providers in the Gulf, where the group harvested subscriber data and internal communications. While public disclosures have waned, threat‑intel monitoring still detects reused infrastructure and occasional re‑branding of their malware families.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the core attribution to the Lebanese GDGS and the group’s espionage motive is high, based on multiple independent security reports and technical analyses. However, gaps remain regarding the full extent of their current operational activity, specific targeting timelines, and any evolution of their toolset post‑2018. Continuous monitoring of emerging IOCs and threat‑intel feeds is recommended to fill these gaps.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
12
Techniques
3
Tools
0
Campaigns
0
IOCs
0
Observed Data
7
Tactics