Dark Caracal (MITRE G0070) is a Lebanon-linked espionage actor originally exposed for global mobile and desktop surveillance, and still active in 2024-2025 with the Bandook backdoor and the newer Poco RAT.
Dark Caracal was publicly detailed in January 2018 by Lookout and the EFF, which attributed the operation to Lebanon's General Directorate of General Security (GDGS) and traced infrastructure to a building in Beirut. MITRE tracks it as G0070 with activity since at least 2012, spanning Android spyware (Pallas) and Windows tooling.
The group's long-standing workhorse is the Bandook Windows backdoor, delivered through phishing and malicious documents; Dark Caracal has historically run broad, multi-sector campaigns rather than narrowly targeted intrusions, which has fueled analyst debate over whether some infrastructure is shared or operated on a for-hire basis. Capabilities include file theft, screenshots, command execution and mobile message/credential collection.
In 2024-2025, Positive Technologies linked a new implant, Poco RAT (named for its POCO C++ libraries), to Dark Caracal, reporting 483 samples between June 2024 and February 2025 and a strategic shift toward large-scale phishing. Notably, that Poco RAT wave concentrated on Spanish-speaking enterprises in Latin America (Venezuela, Dominican Republic, Chile), illustrating the group's global reach beyond its Lebanese base.
MENA relevance stems from the actor's Lebanese origin and regional history; confidence in the activity is high, and the GDGS attribution is medium-to-high based on Lookout/EFF's original technical and infrastructure analysis.