Threat intelligence
- Suspected origin
- Lebanon
- First seen
- 2007-01-01 00:00:00
- Motivation
- Information theft and espionage
- Targeted sectors
- Defense, Education, Financial, Government, Healthcare, Manufacturing, Media, Utilities
- TLP
- WHITE
(Lookout) Lookout and Electronic Frontier Foundation (EFF) have discovered Dark Caracal, a persistent and prolific actor, who at the time of writing is believed to be administered out of a building belonging to the Lebanese General Security Directorate in Beirut. At present, we have knowledge of hundreds of gigabytes of exfiltrated data, in 21+ countries, across thousands of victims. Stolen data includes enterprise intellectual property and personally identifiable information. We are releasing more than 90 indicators of compromise (IOC) associated with Dark Caracal including 11 different Android malware IOCs; 26 desktop malware IOCs across Windows, Mac, and Linux; and 60 domain/IP based IOCs.
Dark Caracal targets include individuals and entities that a nation state might typically attack, including governments, military targets, utilities, financial institutions, manufacturing companies, and defense contractors. We specifically uncovered data associated with military personnel, enterprises, medical professionals, activists, journalists, lawyers, and educational institutions during this investigation. Types of data include documents, call records, audio recordings, secure messaging client content, contact information, text messages, photos, and account data.
Also known as
ATK 27Dark CaracalG0070TAG-CT3
Tooling and malware
BandookCrossRATFinFisher
MITRE ATT&CK techniques
T1005 Data from Local SystemT1113 Screen CaptureT1083 File and Directory DiscoveryT1189 Drive-by Compromise
Coverage 3
threat-intel
BraZetsu is a sophisticated, AI-enhanced Python malware framework developed by the threat actor known as Exilware, used to establish initial access for an underground marketplace called the Infected Marketplace. This mar…

threat-intel
Threat actors linked to Dark Caracal have deployed a new Go-based malware framework, GoCaracal, utilizing an Ethereum smart contract to dynamically update its command-and-control (C2) address. This allows operators to ch…

threat-intel
The Dark Caracal cyber-espionage group, linked to Lebanon, has added a new modular malware framework called GoCaracal to its arsenal. This framework, developed since 2026, is used for data theft, maintaining persistent a…
