ATT&CKGroupsDark Caracal

Dark Caracal

G0070

Threat group.View on attack.mitre.org

About this group

Dark Caracal is threat group that has been attributed to the Lebanese General Directorate of General Security (GDGS) and has operated since at least 2012.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1005
Data from Local System

Dark Caracal collected complete contents of the 'Pictures' folder from compromised Windows systems.

T1027.002
Software Packing

Dark Caracal has used UPX to pack Bandook.

T1027.013
Encrypted/Encoded File

Dark Caracal has obfuscated strings in Bandook by base64 encoding, and then encrypting them.

T1059.003
Windows Command Shell

Dark Caracal has used macros in Word documents that would download a second stage if executed.

T1071.001
Web Protocols

Dark Caracal's version of Bandook communicates with their server over a TCP port using HTTP payloads Base64 encoded and suffixed with the string “&&&”.

T1083
File and Directory Discovery

Dark Caracal collected file listings of all default Windows directories.

T1113
Screen Capture

Dark Caracal took screenshots using their Windows malware.

T1189
Drive-by Compromise

Dark Caracal leveraged a watering hole to serve up malicious code.

T1204.002
Malicious File

Dark Caracal makes their malware look like Flash Player, Office, or PDF documents in order to entice a user to click on it.

T1218.001
Compiled HTML File

Dark Caracal leveraged a compiled HTML file that contained a command to download and run an executable.

T1547.001
Registry Run Keys / Startup Folder

Dark Caracal's version of Bandook adds a registry key to HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run for persistence.

T1566.003
Spearphishing via Service

Dark Caracal spearphished victims via Facebook and Whatsapp.

Software3

Campaigns0

None recorded.

References1

  1. Lookout Dark Caracal Jan 2018 Open source
    Blaich, A., et al. (2018, January 18). Dark Caracal: Cyber-espionage at a Global Scale. Retrieved April 11, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.