Dark Caracal

APT / StateG0070
Techniques (MITRE ATT&CK)12
SourceMITRE ATT&CK
Attribution confidence: 50%

Vexday analysis

Dark Caracal é um grupo de ameaça persistente avançada (APT) atribuído à Diretoria Geral de Segurança Geral do Líbano (GDGS), em operação desde pelo menos 2012. Catalogado no MITRE ATT&CK como G0070, o grupo possui 12 técnicas documentadas e está associado à exploração de 1 CVE conhecida.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity27
Impact: High
T1189T1059.003T1547.001T1083ENTRYInitial accessDrive-byCompromiseEXECExecutionWindows CommandShellPERSPersistenceRegistry Run Keys/ Startup FolderDISCDiscoveryFile and DirectoryDiscoveryCOLLCollectionData from LocalSystem

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 12

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities 1

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Known infrastructure 96

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

md5_hash2d4fe10deb30092875ad0e5327904cd9CrossRATthreatfox
sha1_hashbbdbbbaa2596aa7a8a85fa4d4090c4a0387d7d74CrossRATthreatfox
sha256_hash07b1a32c53c1efab24f54151b1158bad7404374f0dfdee558e7ad80ad278575aCrossRATthreatfox
md5_hash842c0ec2c16fd14a656b3caa6b0d93fcCrossRATthreatfox
sha256_hash8a494cf5613a27de7739d417506a93aa98c51453230f61de36d18d53e5456d97CrossRATthreatfox
sha1_hash0617b24e963b97ba0fa031d09509b05ab06176d5CrossRATthreatfox
sha1_hash0045f51bbd0f4285fc59b60f9652e6a6ad0f8242CrossRATthreatfox
md5_hashf3053fed83a4d313e8aa9cace5db69abCrossRATthreatfox
sha256_hash2a73cad53d7b6ee5df6fce0d9f5761891c6bf42d674130dab5a634ffcd9b3423CrossRATthreatfox
md5_hash62026426767207280fe942f9cc6e9aabCrossRATthreatfox
sha256_hashc1d55538417d22ca041f9a269866ccba8957c40ee698860be340b297713eb8d9CrossRATthreatfox
sha1_hash0950d60a82c2f2f4a2e4b0575ae7a15124245affCrossRATthreatfox
md5_hash13260e2e1ec04400403f6dfd4cb93994CrossRATthreatfox
sha1_hashf54e0ed941e989cfe030e0a7682d669b85612ab5CrossRATthreatfox
sha256_hash53356890a6e72a151d869823f410ecf681731868d241c07ff02d51d6436c3dfdCrossRATthreatfox
md5_hash67e230755c1cf7cfc8d92a98c4caac13CrossRATthreatfox
sha256_hash033eb7a351b65d9aa4e6a19a0be58ea87f579671fe54c3725129589f834c2d06CrossRATthreatfox
sha1_hash57f60f9ca384d9b29794de5446c8fe6fe4e214c2CrossRATthreatfox
sha256_hasha477f89d63408f5ada9698388e4348c65611c81efe19681772e7354d64c2d3edCrossRATthreatfox
sha1_hash8e2e193083339d842f176642387a0b3b2b858540CrossRATthreatfox
md5_hash1c1f469d72d082fb956ca88133d8d8dbCrossRATthreatfox
sha1_hash7e70a6772d83ea168b5c4b15e6067ae51a7d0e05CrossRATthreatfox
md5_hash1314f9049217e0871f8979cf33b1ac63CrossRATthreatfox
sha256_hash38027ca6afc21bd734d86e96b8d3c6016e5afff6d8139b777cb55825a92f8f15CrossRATthreatfox
sha1_hash8698bc1b055be56dce1e2d1cb5634e399a31b1cbCrossRATthreatfox
md5_hash30eff0fbbd41f9172813bd4907d68730CrossRATthreatfox
sha256_hash6599585dcd0455e6c47701e369283af406735c102a6bacaadace6947acc56d18CrossRATthreatfox
sha1_hashaf381a40b1babd7f65f118608a958fc1aa48f115CrossRATthreatfox
sha256_hashe5bccb979fef3945c64622c6ad4461947eca123465f2989d9f4af879fd467890CrossRATthreatfox
md5_hashcc7e9ae7f054d90355af2dd379625ec3CrossRATthreatfox

+96 indicators in total. See them all on the IOCs page.

Dark Caracal uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →