Attributed by Lookout/EFF to the Lebanese General Directorate of General Security (GDGS); some recent operations may reflect a mercenary/for-hire model
Origin
Lebanon
First seen
2018
Last active
2025
Motivation
Espionage
Attribution confidence
medium
MENA targeting
Lebanon (origin); global victims in 20+ countries incl. MENA
Why it mattersState-sponsored / APT actor, medium confidence, documented targeting Lebanon (origin); global victims in 20+ countries incl. MENA (Military, government, activists sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.
[Dark Caracal](https://attack.mitre.org/groups/G0070) collected complete contents of the 'Pictures' folder from compromised Windows systems.(Citation: Lookout Dark Caracal Jan 2018)
[Dark Caracal](https://attack.mitre.org/groups/G0070)'s version of [Bandook](https://attack.mitre.org/software/S0234) communicates with their server over a TCP port using HTTP payloads Base64 encoded and suffixed with the string “&&&”.(Citation: Lookout Dark Caracal Jan 2018)
[Dark Caracal](https://attack.mitre.org/groups/G0070) collected file listings of all default Windows directories.(Citation: Lookout Dark Caracal Jan 2018)
[Dark Caracal](https://attack.mitre.org/groups/G0070) makes their malware look like Flash Player, Office, or PDF documents in order to entice a user to click on it.(Citation: Lookout Dark Caracal Jan 2018)
[Dark Caracal](https://attack.mitre.org/groups/G0070) has used macros in Word documents that would download a second stage if executed.(Citation: Lookout Dark Caracal Jan 2018)
[Dark Caracal](https://attack.mitre.org/groups/G0070)'s version of [Bandook](https://attack.mitre.org/software/S0234) adds a registry key to <code>HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run</code> for persistence.(Citation: Lookout Dark Caracal Jan 2018)
[Dark Caracal](https://attack.mitre.org/groups/G0070) has obfuscated strings in [Bandook](https://attack.mitre.org/software/S0234) by base64 encoding, and then encrypting them.(Citation: Lookout Dark Caracal Jan 2018)
[Dark Caracal](https://attack.mitre.org/groups/G0070) leveraged a compiled HTML file that contained a command to download and run an executable.(Citation: Lookout Dark Caracal Jan 2018)
[Dark Caracal](https://attack.mitre.org/groups/G0070) has used UPX to pack [Bandook](https://attack.mitre.org/software/S0234).(Citation: Lookout Dark Caracal Jan 2018)
Associated software
3 linked · 3 ATT&CK-attributed, 0 curated
Malware and tools this actor is known to use. ATT&CK-attributed rows are MITRE's own software↔group relationships; curated rows fill the gap for MENA actors ATT&CK doesn't track — treat those as analyst assessment, not authoritative attribution.
ATT&CK-attributed · 3
Sourced from MITRE ATT&CK's own uses relationships for this group.
Regional co-occurrence is association, not prediction. These techniques appeared alongside Dark Caracal's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 6 techniques
Advanced Anti-Phishing T1566partialAnti-SpoofingT1566significantMultifactor AuthenticationT1566partialRole Based Access ControlT1059minimalAntimalwareT1027significantAntimalwareT1059significantAntimalwareT1204significantAntimalwareT1204.002significantAntimalwareT1566significantAnti-PhishingT1027.013partialAnti-PhishingT1566significantAntiSpamT1566significant
detect · 6 techniques
Adaptive Application Control IntegrationT1204partialAdaptive Application Control IntegrationT1204.002partialAdvanced Anti-Phishing T1566partialApp GovernanceT1566significantAdvanced Threat HuntingT1189partialAdvanced Threat HuntingT1566significantDefender for Cloud AppsT1071minimalDefender for Cloud AppsT1189partialMicrosoft Defender for IdentityT1059minimalMicrosoft Defender for IdentityT1071minimalPreset Security PoliciesT1189significantPreset Security PoliciesT1204significantPreset Security PoliciesT1566significant
respond · 6 techniques
Advanced Anti-Phishing T1566partialAutomated Investigation and ResponseT1189significantAutomated Investigation and ResponseT1204.002significantAutomated Investigation and ResponseT1566significantIncident ResponseT1059minimalIncident ResponseT1566minimalQuarantine PoliciesT1027significantQuarantine PoliciesT1204significantQuarantine PoliciesT1204.002significantQuarantine PoliciesT1566significantSafe AttachmentsT1204significantSafe AttachmentsT1204.002significantSafe AttachmentsT1566significant
Countermeasures · D3FEND
Defensive techniques that counter Dark Caracal's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.