Dark Caracal is a threat actor linked to the Lebanese General Security Directorate, known for large-scale data exfiltration.
Analyst brief
Dark Caracal is a persistent threat actor linked to the Lebanese General Security Directorate, known for large-scale data exfiltration. Targeting thousands of victims across 21+ countries, it steals enterprise intellectual property and personally identifiable information. Its key TTPs include initial access via Drive-by Compromise and Spearphishing via Service, deployment of dual-use malware like FinFisher, CrossRAT, and Bandook for data collection, and C2 communication over Web Protocols. Defenders should prioritize monitoring suspicious web protocol traffic, unauthorized Registry Run Keys modifications, and detection of encoded/packed files.
Dark Caracal
G0070
unknown
Lookout and Electronic Frontier Foundation (EFF) have discovered Dark Caracal, a persistent and prolific actor, who at the time of writing is believed to be administered out of a building belonging to the Lebanese General Security Directorate in Beirut. At present, we have knowledge of hundreds of gigabytes of exfiltrated data, in 21+ countries, across thousands of victims. Stolen data includes enterprise intellectual property and personally identifiable information.