Dark Caracal
[Dark Caracal](https://attack.mitre.org/groups/G0070) is threat group that has been attributed to the Lebanese General Directorate of General Security (GDGS) and has operated since at least 2012. (Citation: Lookout Dark Caracal Jan 2018)
Properties
- stix_id
- intrusion-set--8a831aaa-f3e0-47a3-bed8-a9ced744dd12
- signal_observed_at
- 2026-09-11T17:55:00+00:00
- type
- intrusion-set
MITRE ATT&CK Techniques (12)
Adversaries may abuse Compiled HTML files (.chm) to conceal malicious code. CHM files are commonly distributed as part of the Microsoft HTML Help syst
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to
Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code
Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection. Encrypting and/or encoding file
Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file s
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to ope
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run key
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality m
Adversaries may perform software packing or virtual machine software protection to conceal their code. Software packing is a method of compressing or
Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems. Spearphishing via service is a sp
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with exi
Adversaries may abuse the Windows command shell for execution. The Windows command shell ([cmd](https://attack.mitre.org/software/S0106)) is the prima
Software & Tools (3)
[Bandook](https://attack.mitre.org/software/S0234) is a commercially available RAT, written in Delphi and C++, that has been available since at least
[CrossRAT](https://attack.mitre.org/software/S0235) is a cross platform RAT.
[FinFisher](https://attack.mitre.org/software/S0182) is a government-grade commercial surveillance spyware reportedly sold exclusively to government a
Explore this actor's full graph with Ninja Signal