◇ SIGN IN
← all actors
apt

Dark Caracal

activemedium confidence
APT / State-sponsored
Dark Caracal
Attribution
Attributed by Lookout/EFF to the Lebanese General Directorate of General Security (GDGS); some recent operations may reflect a mercenary/for-hire model
Origin
Lebanon
First seen
2018
Last active
2025
Motivation
Espionage
Confidence
medium
MENA targeting
Lebanon (origin); global victims in 20+ countries incl. MENA
Sectors
Military, government, activists, individuals
MITRE ATT&CK
Why it mattersState-sponsored / APT actor, medium confidence, documented targeting Lebanon (origin); global victims in 20+ countries incl. MENA (Military, government, activists sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Dark Caracal (MITRE G0070) is a Lebanon-linked espionage actor originally exposed for global mobile and desktop surveillance, and still active in 2024-2025 with the Bandook backdoor and the newer Poco RAT.

History

Dark Caracal was publicly detailed in January 2018 by Lookout and the EFF, which attributed the operation to Lebanon's General Directorate of General Security (GDGS) and traced infrastructure to a building in Beirut. MITRE tracks it as G0070 with activity since at least 2012, spanning Android spyware (Pallas) and Windows tooling.

The group's long-standing workhorse is the Bandook Windows backdoor, delivered through phishing and malicious documents; Dark Caracal has historically run broad, multi-sector campaigns rather than narrowly targeted intrusions, which has fueled analyst debate over whether some infrastructure is shared or operated on a for-hire basis. Capabilities include file theft, screenshots, command execution and mobile message/credential collection.

In 2024-2025, Positive Technologies linked a new implant, Poco RAT (named for its POCO C++ libraries), to Dark Caracal, reporting 483 samples between June 2024 and February 2025 and a strategic shift toward large-scale phishing. Notably, that Poco RAT wave concentrated on Spanish-speaking enterprises in Latin America (Venezuela, Dominican Republic, Chile), illustrating the group's global reach beyond its Lebanese base.

MENA relevance stems from the actor's Lebanese origin and regional history; confidence in the activity is high, and the GDGS attribution is medium-to-high based on Lookout/EFF's original technical and infrastructure analysis.

Notable campaigns

2018
Dark Caracal (Lookout/EFF disclosure)
Global mobile (Pallas) and desktop surveillance operation attributed to Lebanon's GDGS, exfiltrating data from thousands of victims.
2020-2024
Bandook campaigns
Sustained phishing distribution of the Bandook Windows backdoor against corporate and government targets across multiple regions.
2024-2025
Poco RAT
Positive Technologies attributed a new C++ RAT to Dark Caracal, with 483 samples in a large phishing campaign hitting Spanish-speaking LATAM enterprises.