cvekit
LIVE
Threat actors

Dark Caracal

crimewareLBvia MISP

3 CVEs attributed

Aliases1

G0070
Lookout and Electronic Frontier Foundation (EFF) have discovered Dark Caracal, a persistent and prolific actor, who at the time of writing is believed to be administered out of a building belonging to the Lebanese General Security Directorate in Beirut. At present, we have knowledge of hundreds of gigabytes of exfiltrated data, in 21+ countries, across thousands of victims. Stolen data includes enterprise intellectual property and personally identifiable information.

Attributed CVEs3

CVEDescriptionSeverityEPSSFlagsModified
CVE-2017-8759

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."

HIGH7.8
89%p100
KEVPoC
2026-06-17
CVE-2026-18577

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

HIGH8.1
54%p99
KEVPoC
2026-08-04
CVE-2026-18556

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

HIGH7.4
40%p99
KEVPoC
2026-08-05