Skip to content
July 26, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Malware
  • CSE CybSec ZLAB releases Malware Analysis Report: Dark Caracal APT
  • Malware

CSE CybSec ZLAB releases Malware Analysis Report: Dark Caracal APT

Do Son February 14, 2018 3 minutes read
Dark Caracal
Add Daily CyberSecurity as a preferred source on Google

According to securityaffairs February 12, researchers from CSE’s CybSec ZLAB lab analyzed a sample set of Pallas malware families used by the Lebanese APT espionage team Dark Caracal in hacking operations. The analysis pointed out that the malware was able to collect a large amount of sensitive data for the target application and send it to the C&C server via an encrypted URL that was decrypted at a run time.

Actually, Dark Caracal has been active since 2012, but until recently it was found to be a formidable threat in the online arena.

According to previous reports, a joint investigation by the Electronic Frontier Foundation Frontier Foundation and the security company Lookout found that the Dark Caracal APT, a surveillance and espionage organization associated with the Lebanese General Security Agency, stole large amounts of data from Android phones and Windows PCs around the world and recently hackers Dark Caracal spyware platform sold to some countries to monitor. According to the researchers, this espionage has spread malware that contains trojans through the manufacture of large numbers of fake Android applications and using social projects such as phishing email or fake social network information, which has involved 21 countries from the past 21 countries Journalists, military personnel, companies and other sensitive information (SMS, call history, archives, etc.).

Dark Caracal Impact Area

Researchers said one of Dark Caracal’s most powerful advertising campaigns, which began in the first months of last year, uses a series of trojanized Android applications designed to steal sensitive data from victims’ mobile devices. It is reported that the Trojans injected into these applications are Pallas researchers have found.

So how do attackers step by step to steal data?

Attackers use “repackaging” technology to generate their malware samples by starting with a legitimate application and injecting malicious code before rebuilding the apk. In general, the target application belongs to a specific category, such as Whatsapp, Telegram, Primo), secure chat app (Signal, Threema), or software related to secure navigation (Orbot, Psiphon).

After the malware was made, attackers used social engineering techniques to trick victims into installing malware such as using SMS, Facebook messages, or Facebook posts to trick victimized users into downloading new and popular applications through a specific web address. Currently, these trojanized applications Are hosted on the same URL.

Pictured – Dark Caracal Repository – Malicious site

When a user’s device is infected, an attacker uses a malicious application to collect large amounts of data and send it to the C&C server through an encrypted URL that is decrypted at runtime.

The following is the specific function of the Trojan:

– read sms

– send text messages

– Record the call

– Read the call history

– Retrieve account and contact information

– Collect all stored media and send them to C2C

– Download and install additional malware

– Display a phishing window to attempt to steal credentials

– Retrieve a list of all devices connected to the same network

Read more

ZLAB Malware Analysis Report: Dark Caracal APT – The Pallas Family

Source: SecurityAffairs 

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.


We respect your inbox. Unsubscribe anytime.

Related coverage

  • Spirals Ransomware Encrypts a South Asian IT Network in Under 24 Hours
  • Lazarus Group Attacks with DreamLoader Malware, Leveraging DLL Sideloading and Microsoft Graph API for Stealth C2
  • Agenda Ransomware Evolves with NETXLOADER and SmokeLoader in Global Campaigns
  • Cryptocurrency Users Targeted by Invasive New Malware Campaign
  • Massive Cyber Campaign Exploits 4,000 ISP IPs in the U.S. and China for Credential Theft and Cryptojacking
Track all actively exploited CVEs →

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Dark Caracal

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2021-27137CVSS 8.1
    An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-66013CVSS 9.3
    OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration...
  • CVE-2026-66012CVSS 10.0
    SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp...
  • CVE-2026-61884CVSS 9.8
    The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation...
  • CVE-2026-62379CVSS 9.8
    ## Summary A pre-authentication remote code execution vulnerability affects OpenAM. The remote...
  • CVE-2026-62263
    ### Summary The GHSA-6c99-87fr-6q7r fix wrapped WebAuthn authenticator deserialization in an `ObjectInputFilter`...
  • CVE-2026-62835CVSS 9.3
    Improper authorization in Azure Portal allows an unauthorized attacker to disclose information...
  • CVE-2026-48021CVSS 9.1
    In epa4all, prior to version 2026-05-20, an attacker who can intercept the...
  • CVE-2026-59940CVSS 9.8
    ## Summary A type confusion issue in `seroval.fromJSON()` allowed attacker-controlled JSON input...
  • CVE-2026-58630CVSS 10.0
    Improper access control in Azure App Service allows an unauthorized attacker to...
  • CVE-2026-57106CVSS 10.0
    Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.