Lebanese Cedar, also tracked as Volatile Cedar and associated with aliases including AMETHYST RAIN and VolcanicTimber, is a Lebanese threat actor active since at least 2012 and widely assessed as aligned with Hezbollah. Reporting has also noted possible coordination with Iran-linked actors associated with the Ministry of Intelligence and Security. The group has conducted cyber-espionage operations against individuals, companies, and institutions, with a particular history of intrusions targeting telecommunications providers, internet service providers, and public-facing web infrastructure across the Middle East, Europe, and the United States. The actor is known for exploiting n-day vulnerabilities in internet-facing servers and web applications to obtain initial access, including targeted exploitation of public-facing web servers following both automated and manual vulnerability discovery. Lebanese Cedar has performed vulnerability scanning and reconnaissance against target servers, then established persistence through web shells and IIS components. Post-compromise activity has included command execution, deployment of additional tools, use of Meterpreter, and operation of the custom Explosive RAT malware family. The group has also stolen legitimate network credentials to support continued access and espionage objectives. Victimology associated with Lebanese Cedar includes operations affecting Lebanon, Israel, Palestine, Egypt, the United States, and the United Kingdom. Sector targeting directly supported by available reporting includes telecommunications and internet service providers. The actor's activity is characterized primarily as politically and ideologically motivated espionage rather than financially motivated crime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
The following analytic detects attempts to exploit CVE-2022-26134, an unauthenticated remote code execution vulnerability in Confluence... This activity is significant as it allows attackers to execute arbitrary code on the Confluence server without authentication, potentially leading to full system compromise.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
3 more CVEs tied to this actor tracked in Mallory.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed incidentally in ATT&CK annotation metadata.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Listed as a threat actor associated with web shell persistence activity in the context of this VMware Workspace ONE web shell detection.
Listed as a threat actor associated with exploitation of public-facing applications and malware/tool upload activity relevant to Confluence exploitation detection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.