Dark Caracal is a Lebanon-linked cyberespionage threat group associated with Lebanon’s General Directorate of General Security (GDGS). Active since at least 2012, it has targeted government and military entities, businesses, journalists, activists, and individuals, including victims in Latin America, Europe, Asia, and North America. The group has used phishing, malicious websites, trojanized mobile applications, malicious documents and macros, and files disguised as legitimate software or documents for initial access. Its known malware includes Pallas, modified Bandook remote-access trojans, and the modular GoCaracal framework. In June 2026, Dark Caracal was assessed with medium confidence to have compromised a Venezuelan communications-sector organization. The operation used Spanish-language financial and tax lures, weaponized SVG attachments, URL-shortening and redirect chains, and archived payloads to deploy GoCaracal alongside an updated Bandook variant and a Delphi loader. GoCaracal includes a lightweight access-oriented profile for host profiling, encrypted command-and-control, shell access, payload execution, and shellcode injection, and an extended profile for file and system discovery, browser credential and cookie collection, keylogging, file collection, SOCKS5 proxying, hidden browser interaction, WebRTC remote desktop access, and persistence. The extended framework can obtain replacement off-chain command-and-control configuration from Ethereum smart contracts after primary infrastructure failures. Dark Caracal has also used Windows malware to capture screenshots, collect directory listings and user files, and establish Registry-based persistence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
213 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as an annotated actor associated with the detection technique.
Cyberespionnage ciblant une organisation de télécommunications vénézuélienne au moyen du framework GoCaracal et d’une variante actualisée de Bandook. L’opération commence par des courriels d’hameçonnage financiers ou fiscaux en espagnol et fournit des capacités de persistance, de collecte, d’enregistrement des frappes, de vol de cookies, d’accès distant, de proxy SOCKS5 et de repli C2 fondé sur Ethereum.
Conducted a targeted espionage intrusion against a Venezuelan communications organization, deploying the GoCaracal modular framework and an updated Bandook backdoor. The group is modernizing its malware and C2 infrastructure while retaining established phishing-led tradecraft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.