APT / THREAT GROUP
Dark Caracal
🇱🇧LB-attributed
1
campaigns
2
aliases
Last seen:Mar 17, 2026
Intelligence Profile
[Dark Caracal](https://attack.mitre.org/groups/G0070) is threat group that has been attributed to the Lebanese General Directorate of General Security (GDGS) and has operated since at least 2012. (Citation: Lookout Dark Caracal Jan 2018)
Threat Analysis
Dark Caracal is a known-sophistication threat actor attributed to LB, engaged in cyber operations with a primary motivation of unknown activity patterns.
Known Campaigns
Dark Caracal — Active Operations March 2026
Dark Caracal is a unknown-motivation threat actor attributed to LB. Lookout and Electronic Frontier Foundation (EFF) have discovered Dark Caracal, a persistent and prolific actor, who at the time of writing is believed to be administered out of a building belonging to the Lebanese General Security Directorate in Beirut. At present, we have knowle...
ACTIVEMEDIUM2026
External References
Quick Facts
TypeAPT / Threat Group
Origin🇱🇧 LB
Aliases2
SourceMalpedia
Also Known As
G0070Dark Caracal
Research Links
Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.