Activity timeline
Dark Caracal appears in 2 tracked threats between and .
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
- T1055 Process Injection — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
- T1057 Process Discovery — Discoveryobserved in 2 of 2 tracked threats
- T1012 Query Registry — Discoveryobserved in 1 of 2 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 1 of 2 tracked threats
- T1021.005 VNC — Lateral Movementobserved in 1 of 2 tracked threats
- T1056 Input Capture — Collectionobserved in 1 of 2 tracked threats
- T1056.001 Keylogging — Collectionobserved in 1 of 2 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 1 of 2 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 1 of 2 tracked threats
- T1090 Proxy — Command and Controlobserved in 1 of 2 tracked threats
- T1102.001 Dead Drop Resolver — Command and Controlobserved in 1 of 2 tracked threats
- T1112 Modify Registry — Defense Impairmentobserved in 1 of 2 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
- T1204 User Execution — Executionobserved in 1 of 2 tracked threats