Threat group.View on attack.mitre.org
Dark Caracal is threat group that has been attributed to the Lebanese General Directorate of General Security (GDGS) and has operated since at least 2012.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Dark Caracal collected complete contents of the 'Pictures' folder from compromised Windows systems. |
| T1027.002 Software Packing |
Dark Caracal has used UPX to pack Bandook. |
| T1027.013 Encrypted/Encoded File |
Dark Caracal has obfuscated strings in Bandook by base64 encoding, and then encrypting them. |
| T1059.003 Windows Command Shell |
Dark Caracal has used macros in Word documents that would download a second stage if executed. |
| T1071.001 Web Protocols |
Dark Caracal's version of Bandook communicates with their server over a TCP port using HTTP payloads Base64 encoded and suffixed with the string “&&&”. |
| T1083 File and Directory Discovery |
Dark Caracal collected file listings of all default Windows directories. |
| T1113 Screen Capture |
Dark Caracal took screenshots using their Windows malware. |
| T1189 Drive-by Compromise |
Dark Caracal leveraged a watering hole to serve up malicious code. |
| T1204.002 Malicious File |
Dark Caracal makes their malware look like Flash Player, Office, or PDF documents in order to entice a user to click on it. |
| T1218.001 Compiled HTML File |
Dark Caracal leveraged a compiled HTML file that contained a command to download and run an executable. |
| T1547.001 Registry Run Keys / Startup Folder |
Dark Caracal's version of Bandook adds a registry key to |
| T1566.003 Spearphishing via Service |
Dark Caracal spearphished victims via Facebook and Whatsapp. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.