Karkadann is a threat cluster associated with strategic web compromises and watering-hole operations focused primarily on the Middle East, especially Yemen. The activity documented under this name involved compromising legitimate high-profile websites and modifying their content or embedded scripts to profile visitors, selectively identify intended targets, and redirect chosen victims toward a likely browser remote-code-execution exploit chain. The compromised websites functioned mainly as an initial access vector for highly selective follow-on exploitation rather than as the final payload host. Observed operations included two major waves in 2020 and 2021. In the earlier wave, attacker-controlled JavaScript was injected into compromised sites to collect browser and operating-system information, perform geolocation checks, and communicate with attacker infrastructure using encrypted exchanges. In the later wave, the operators adopted stealthier tradecraft, including modifying existing site JavaScript instead of only injecting code into page HTML, suppressing repeated delivery through cookies, and later using FingerprintJS Pro to gather extensive browser and device attributes. Infrastructure in the second wave was capable of returning executable JavaScript to run in the victim browser context, indicating a flexible post-fingerprinting delivery mechanism. Targeting centered on visitors to government, media, diplomatic, and defense-related websites connected to Yemen and the broader Middle East, with additional compromises affecting Syrian, Lebanese, Iranian, Italian, South African, and German-linked web properties. The victimology indicates an espionage-oriented collection mission focused on carefully selected individuals rather than broad indiscriminate exploitation. Tradecraft included masquerading attacker infrastructure as legitimate analytics, content-delivery, and URL-shortening services to blend into normal web traffic. Karkadann has been linked through infrastructure and tradecraft overlaps to activity associated with Candiru, an Israeli commercial spyware vendor. The available evidence supports an assessment that the watering-hole operators were likely customers or users of Candiru capability rather than Candiru itself. No high-confidence public evidence in this record identifies the ultimate exploit payload delivered to selected victims, consistent with an operation designed to preserve expensive browser exploits and minimize exposure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
25 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.