A threat group targeting Middle Eastern government and media sites via watering hole attacks and JavaScript injection.
Analyst brief
Karkadann (Piwiks) has been active since at least October 2020, targeting government bodies and news outlets in the Middle East. The group primarily uses watering hole attacks, compromising high-profile websites to inject malicious JavaScript code. Karkadann is linked to the commercial spyware company Candiru, suggesting the group may utilize multiple spyware technologies. Defenders should monitor key media and government websites in the Middle East, focus on detecting suspicious JavaScript injections, and deploy multi-layered spyware detection mechanisms.
Karkadann
Piwiks
unknown
Karkadann is a threat actor that has been active since at least October 2020, targeting government bodies and news outlets in the Middle East. They have been involved in watering hole attacks, compromising high-profile websites to inject malicious JavaScript code. The group has been linked to another commercial spyware company called Candiru, suggesting they may utilize multiple spyware technologies. There are similarities in the infrastructure and tactics used by Karkadann in their campaigns.
In which region does the Karkadann actor operate, and who are its primary targets?+
Karkadann primarily targets government bodies and news outlets in the Middle East.
What tactic does Karkadann use to compromise high-profile sites, and what risk is heightened by its linked company?+
Karkadann uses watering hole attacks to compromise sites and inject malicious JavaScript code. Its link to Candiru suggests it may have access to multiple spyware technologies.