Dark Caracal is a Lebanon-linked cyberespionage threat group associated with Lebanon’s General Directorate of General Security. Active since at least 2012, it has targeted government and military entities, businesses, journalists, activists, and individuals across multiple regions, including Latin America, Europe, Asia, and North America. The group has used phishing, malicious websites, trojanized mobile applications, document lures, and malicious attachments to gain access. Its malware ecosystem includes Bandook, Pallas, and the Go-based GoCaracal framework. GoCaracal supports host profiling, encrypted command-and-control, remote shell access, payload delivery and execution, process injection, file and directory discovery, browser credential and cookie collection, keylogging, SOCKS proxying, concealed browser activity, remote desktop access, and persistence. GoCaracal can obtain replacement off-chain command-and-control configuration from Ethereum smart contracts after repeated primary command-and-control failures. Dark Caracal has also used Windows Registry Run-key persistence, HTTP-based command-and-control, screenshot capture, and collection of files and image folders. In June 2026, the group was assessed with medium confidence to have compromised a Venezuelan communications organization using Spanish-language financial and tax-themed phishing lures, weaponized SVG attachments, GoCaracal, a Delphi loader, and Bandook.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
213 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a targeted espionage intrusion against a Venezuelan communications organization, deploying the GoCaracal modular framework and an updated Bandook backdoor. The group is modernizing its malware and C2 infrastructure while retaining established phishing-led tradecraft.
Conducting a Spanish-language phishing-led espionage campaign against a Venezuelan communications organization, using weaponized SVG files and a Delphi loader to deploy GoCaracal and the Bandook backdoor. The extended GoCaracal variant supports host reconnaissance, file and browser-data collection, keylogging, proxying, covert remote-desktop access, persistence, and Ethereum smart-contract-based C2 fallback.
Cyberespionage activity targeting a Venezuelan communications organization using Spanish-language financial and tax phishing lures. The group delivered GoCaracal and Bandook through weaponized SVG attachments and archives, and used Ethereum smart contracts as a fallback mechanism to recover replacement C2 configuration when its primary C2 infrastructure is unavailable.
Cyberespionage activity targeting Latin American organizations. The group used Spanish-language financial and tax-themed phishing emails with weaponized SVG attachments, shortened-link redirects, and malware archives. Its new GoCaracal framework provides initial access and extended surveillance capabilities, including an Ethereum smart-contract-based fallback mechanism to recover replacement C2 addresses after infrastructure disruption.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.