Adversary-emulation profile for Dark Caracal (G0070), a Lebanese state-linked cyber-espionage and surveillance actor attributed to the General Directorate of General Security (GDGS), operating since at least 2012.
49
53%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Fix and improve this skill with Tessl
tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/dark-caracal/SKILL.mdDark Caracal (MITRE ATT&CK G0070) is a cyber-espionage and surveillance group attributed to Lebanon's General Directorate of General Security (GDGS), operating since at least 2012. The group is best characterized by its mobile-first surveillance approach — deploying trojanized Android messaging apps (Pallas) to harvest SMS, call logs, contacts, photos, and real-time audio/video — combined with cross-platform desktop RATs (Bandook, CrossRAT) and the commercial spyware FinFisher. Dark Caracal relies on relatively simple social engineering — phishing via Facebook and WhatsApp, watering holes, and trojanized applications masquerading as popular software — rather than advanced zero-day exploitation. Despite this simplicity, the group has compromised thousands of victims across 20+ countries, exfiltrating hundreds of thousands of files and text messages. Evidence suggests the group may also operate as a cyber-mercenary / hack-for-hire entity, conducting campaigns on behalf of other governments (notably Kazakhstan in Operation Manul).
cmd.exe for post-compromise command execution; Word document macros invoke the shell to download second-stage payloads.ShellExecuteW() and other Win32 APIs directly for execution.HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run for persistence; CrossRAT and FinFisher also use Run keys./Library/LaunchAgents/) for persistence across reboots.iexplore.exe process and injects its payload via process hollowing — the group's signature injection technique.iexplore.exe via process hollowing to evade detection.&&&.| Name | ATT&CK ID | Type | Public/Custom |
|---|---|---|---|
| Bandook | S0234 | Windows RAT (Delphi/C++, process hollowing, keylogger, screen/audio/video capture) | Custom (origin: commercial RAT by Lebanese dev "PrinceAli", 2007; heavily customized) |
| CrossRAT | S0235 | Cross-platform Java RAT (Windows/macOS/Linux, screenshots, file manipulation) | Custom |
| Pallas | S0399 | Android mobile surveillance trojan (trojanized messaging apps) | Custom |
| FinFisher | S0182 | Commercial Windows/mobile spyware (full-spectrum surveillance) | Commercial (Gamma International) |
| Poco RAT | (no ATT&CK software ID assigned) | Delphi-based Windows RAT (credential harvesting, screen capture, command execution) | Custom (attributed 2024-2025) |
Note: Bandook originated as a commercially available RAT circa 2007 but has been extensively modified by Dark Caracal with custom loaders, code-signing, steganography-based payload construction, and Twofish-encrypted variants. Poco RAT shares dropper architecture with Bandook (process hollowing into
iexplore.exe, dynamic API resolution) and is assessed as Bandook's successor.
Authorized-use caveat: Execute the following ONLY within the documented rules of engagement, target scope, and time window of an authorized engagement. Never deploy mobile surveillance implants or trojanized messaging apps outside an explicitly sanctioned, isolated lab.
Map Dark Caracal's signature plays to Decepticon's own capabilities:
.rev (WinRAR recovery volume) archive to evade AV, (2) uses steganography (payload hidden in PNG images within a zip), (3) employs process hollowing into iexplore.exe for injection, and (4) is signed with a valid code-signing certificate. This chain reproduces the Bandook/Poco RAT delivery exactly.HKCU\Software\Microsoft\Windows\CurrentVersion\Run); Linux — XDG Autostart entry in ~/.config/autostart/; macOS — Launch Agent plist in ~/Library/LaunchAgents/. Deploy all three to demonstrate the group's multi-OS capability.Pictures folder and default user directories, take periodic screenshots, activate webcam and microphone capture, and log keystrokes. This comprehensive surveillance is the group's defining operational pattern.&&& suffix marker (Bandook's signature C2 pattern). Use AES-encrypted communications and support a raw TCP socket fallback channel.WINWORD.EXE spawning cmd.exe or powershell.exe.iexplore.exe spawned by non-standard parents (Word, PowerShell, cmd.exe); alert on suspended process creation followed by NtUnmapViewOfSection/WriteProcessMemory API calls; deploy behavioral endpoint detection for process hollowing patterns.hh.exe execution and its child processes; block .chm files at the email gateway; alert on hh.exe spawning network connections or downloading executables..rev (WinRAR recovery volume) archives.&&& suffix marker; detect beaconing patterns over TCP to known-bad IPs; alert on raw TCP socket connections from user processes..rev file downloads (uncommon extension in enterprise environments); alert on WinRAR recovery volume files being extracted and executed.4484f85
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.