Dark Caracal

THREAT ACTOR PROFILE

Dark Caracal

Dark Caracal

Dark Caracal

Dark Caracal is a cyber-mercenary group active since around 2012 that runs espionage-for-hire across multiple regions. Once known for mobile surveillance tied to Lebanese interests, it now focuses heavily on Spanish-speaking Latin America, using the long-running Bandook backdoor and a new Go-based framework with Ethereum blockchain fallback for C2.

Lebanon-linked (mercenary)

Government / Private sector

First seen

2012

Latest IOC

-

IP indicators

Hosts

SHA256 hashes

Posts

NAMES AND ALIASES

The Dark Caracal mercenary group

Dark Caracal is tracked mostly under its own name as a cyber-mercenary operation. It is one entry among the mercenary and state actors we track, and its recent Latin America focus overlaps with actors like APT-C-36.

-

-

-

GROUP PROFILE

Espionage for hire, now focused on Latin America

Dark Caracal is a hack-for-hire operation first exposed for mobile and desktop surveillance tied to Lebanese General Security. It has since run campaigns for various clients, and its recent activity centers on Spanish-speaking organizations in Latin America.

Our record places it as Lebanon-linked and ties it to espionage across government and private-sector targets. A 2026 intrusion hit a Venezuelan communications organization.

The group's mainstay is the Bandook backdoor, delivered through phishing. In 2026 it added GoCaracal, a modular Go framework with a notable twist: it resolves C2 addresses from Ethereum blockchain transactions as a fallback when primary infrastructure is disrupted.

Facts:

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Victims reported in our records and posts:

-

-

-

-

-

-

ATTACK LIFECYCLE

SVG phishing into Bandook and GoCaracal

The stages below come from 2026 Dark Caracal activity in posts we track on our IOC Hunter feed.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

MALWARE AND TOOLING

Bandook, GoCaracal and Poco RAT

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

CVES EXPLOITED

Access through phishing, not exploits

Dark Caracal's intrusions in our records rely on social engineering, weaponized SVG and archive attachments, and the Bandook and GoCaracal backdoors rather than on exploiting specific software vulnerabilities, so this profile does not list a confirmed exploited-CVE set. Detection should focus on the phishing-to-Bandook chain and GoCaracal's blockchain-based C2 fallback.

Dark Caracal

IOCS FROM HUNT.IO PLATFORM

Latest IOCs

We currently track - IP indicators, - hosts, and - SHA256 hashes for Akira across - intelligence posts, with the most recent indicator dated -. The sample below is limited to indicators from the latest posts. It is not the full set.

Dark Caracal

Hosting Company

IPs

Date

Hosting Company

IPs

Date

144.126.202.227

LameHug exfil

06-17

Showing a sample of recent indicators

Get the complete

Dark Caracal

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

Dark Caracal

IOC set, full IP, host and hash history.

NOTABLE CAMPAIGNS

GoCaracal and Ethereum-based C2

Recent reporting tracks Dark Caracal's new framework and its Latin America focus.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

Showing a sample of recent indicators

Get the complete

Dark Caracal

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

Dark Caracal

IOC set, full IP, host and hash history.