Dark Caracal is a long-running cyber-mercenary espionage actor associated with digital surveillance operations conducted on behalf of government interests in Lebanon and Kazakhstan. The group is widely known for using the Bandook remote access trojan on Windows and the Pallas mobile malware family, and has remained active across multiple years and regions, including renewed campaigns in Latin America. Dark Caracal has targeted government entities as well as organizations in financial services, energy, food, health care, education, information technology, and legal sectors. Reported victim geography includes Lebanon, the United States, Singapore, Cyprus, Chile, Italy, Turkey, Switzerland, Indonesia, Germany, the Dominican Republic, and Venezuela, with more recent activity heavily concentrated in the Dominican Republic and Venezuela. The actor relies heavily on social engineering and user-driven infection chains rather than exploit-dependent intrusion. Observed delivery methods include phishing, malicious Microsoft Office documents with macros, lure files disguised as common software or document types, and trojanized mobile applications distributed through watering-hole websites. On mobile platforms, Dark Caracal has used standard HTTP communications for implant control. On Windows, its Bandook variants have used HTTP-based command and control, including Base64-encoded HTTP payloads over TCP, and later variants expanded command support substantially while adding capabilities such as remote desktop control, webcam access, screen recording, file operations, and modular extension through additional libraries. Dark Caracal demonstrates mature surveillance and collection tradecraft. Documented capabilities include screenshot capture, file and directory discovery, collection of file listings from default Windows directories, theft of files from compromised systems, and targeted collection of user content such as image folders. Bandook-associated tooling has also been observed using process hollowing and maintaining persistence through Registry Run-style autostart mechanisms. The group has shown iterative malware development over time, including multiple Bandook variants with differing command sets and improved operational security compared with earlier campaigns. Dark Caracal is best characterized as a politically aligned espionage-for-hire actor focused on covert surveillance, data theft, and long-term access rather than disruptive or ransomware operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
165 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an associated threat actor in detection annotations for Ghostscript exploitation; no specific campaign activity is described in this reference.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Listed as a threat actor associated with the malicious file execution technique detected by this analytic.
Listed as a threat actor associated with Windows Command Shell execution behavior relevant to this detection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.