Dark Caracal

APT / StateG0070 ↗
Techniques (MITRE ATT&CK)12
SourceMITRE ATT&CK
Attribution confidence: 50%
Also known as:G0070

About the group

Dark Caracal is threat group that has been attributed to the Lebanese General Directorate of General Security (GDGS) and has operated since at least 2012.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity27
Impact: High
T1189T1059.003T1547.001T1083ENTRYInitial accessDrive-byCompromiseEXECExecutionWindows CommandShellPERSPersistenceRegistry Run Keys/ Startup FolderDISCDiscoveryFile and DirectoryDiscoveryCOLLCollectionData from LocalSystem

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 12

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities 1

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Known infrastructure 156

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

md5_hasha4704f0e3a3ca3efc1078af02105d30fCrossRATthreatfox
sha1_hash6888baa9ec4188a3a11cf18a394e69e504743aa9CrossRATthreatfox
sha256_hash034174f5266a4276cf29cfdb23fc3fa52699438ff60c8055b7df12c88341a49bCrossRATthreatfox
sha1_hasheb71f02fb2de58cb0b68a868d06213620feb98c7CrossRATthreatfox
md5_hashbfc0848e67feb2b80c7bf5ba9c1efe27CrossRATthreatfox
sha256_hash2b0ca329e37f6cf14c33735d1c0d2e85d47354b9839798bfef7beb19df664975CrossRATthreatfox
sha1_hashbc2745c026a8d0efe3849978221dccb0bb3906dbCrossRATthreatfox
md5_hash1ad3729976f26d9d7ea44e2a7195b572CrossRATthreatfox
sha256_hash0693e042dd629efb54a385e8fee6cd00c7a54543d31bceb3f790365a72e55448CrossRATthreatfox
sha1_hashef8e4943611382bc5976388286d0a9bd413e4bdbCrossRATthreatfox
md5_hash5a12e4935f8b9504f6a2d0459478ea64CrossRATthreatfox
sha256_hash9121ef0f2d7b2cc3c887420ecb1eae214db9cb780433d11565ab8c98a6ad99ecCrossRATthreatfox
sha1_hashbcf93d6e09d1f50f5c32565b1e9e4486af6a5e4dCrossRATthreatfox
md5_hash8da0682a940f6fe660af38de8e003111CrossRATthreatfox
sha256_hashd19aec3e4cdc4a3e9d59a7f535891b5d00d2cbd6cbe403800625ba5536ee4534CrossRATthreatfox
md5_hash0c7dd3b979c3fdeba56c6ae312345548CrossRATthreatfox
sha1_hash2cbd1f5b16cc5e17be51a801de7fed705a2336a5CrossRATthreatfox
sha256_hashfb48f55e9e2b1ef2d904b0f06547ce698bcb151b43dd032fc7257a7c0f940bd4CrossRATthreatfox
md5_hash0958ba3a7e13502ab3582b76c42b0af3CrossRATthreatfox
sha1_hash3a7d43913b70b5cb6543f007b33d7c2547d08019CrossRATthreatfox
sha256_hashc07fc51b54d37857ee131eb9a698fff42dbb9460abc9b0103e04a20d51851d15CrossRATthreatfox
md5_hash895e427449556e15d357670e9e499dcbCrossRATthreatfox
sha1_hasha51a18b3908126f1f1c11895e92c1d65230903beCrossRATthreatfox
sha256_hash744437d93633c87382f9d1a1fdf0c1a3a908c5f9e0435bb480771dbdc0282faeCrossRATthreatfox
md5_hashf4a21c6c2dbc446fadce7744a112cb14CrossRATthreatfox
sha256_hash73297baf09544ba19037911c2a5352069622ebdbccae2ae15d7150c718dd81f4CrossRATthreatfox
sha1_hashe9f57b057380b8da867c57a26550ea509e5cb3e8CrossRATthreatfox
sha1_hash9a0bf53c0238db10d5072e1eed3e899476a93f08CrossRATthreatfox
md5_hash778536300231f9b2986156aca82877a2CrossRATthreatfox
sha256_hash0fb478ddeb84afbe562320708adf25611b302d4e89bc0557d070dd6e89dec6a3CrossRATthreatfox

+156 indicators in total. See them all on the IOCs page.

Dark Caracal uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →