SophiaX
🔍
LIVE
· New victim: cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· New victim: 4,078 new IOCs ingested in last 24h cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· 4,078 new IOCs ingested in last 24h

Dark Caracal

🏛️ Nation-StateLast active: 2026-08-26First seen: 2018-10-17G0070 ↗
5
linked CVEs
Also known as
G0070
Targeted industries
Telecommunications
Targeted regions
BrazilChileColombiaEcuadorEl SalvadorUruguayVenezuela, Bolivarian Republic of
Lookout and Electronic Frontier Foundation (EFF) have discovered Dark Caracal, a persistent and prolific actor, who at the time of writing is believed to be administered out of a building belonging to the Lebanese General Security Directorate in Beirut. At present, we have knowledge of hundreds of gigabytes of exfiltrated data, in 21+ countries, across thousands of victims. Stolen data includes enterprise intellectual property and personally identifiable information.
Source: misp_galaxy · Collected: 2026-09-19
⚡ Vulnerabilities & Exploits5 CVEs
threat_actor_cve → cves / exploits.cve_ids
CVE-2026-28323
suspected

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.

CVSS 9.8
CVE-2026-28299
suspected

SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the Web Help Desk server to crash due to insufficient memory.

CVSS 8.2
CVE-2026-18577
suspected

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

CVSS 8.1
KEV
CVE-2026-50656
suspected

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

CVSS 7.8
CVE-2026-18556
suspected

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

CVSS 7.4
KEV
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
MITRE ATT&CK Techniques Used12 techniques
Across 8 tactics
🛰️ Infrastructure & IOCs39
domaindocumentodigital.cloud—2026-08-26
domaingetpdfdigital.cloud—2026-08-26
ip77.110.105.244—2026-08-26
ip82.117.87.138—2026-08-26
ip82.117.87.192—2026-08-26
sha2568c03d072df2e1bf14b0c00a8ab99834138c8b69f301849bf09cb44394e916015—2026-08-26
domainvisualizarpdf.online—2026-08-26
ip193.233.245.52—2026-08-26
md527cc65cb6261ef0d584287cf09bdafcc—2026-08-26
domaincontabilidad.icu—2026-08-26
ip185.125.101.181—2026-08-26
ip109.172.95.121—2026-08-26
sha25677f7ad29f4a8037ee5f38d3d87fb91cfd97cb8f7fa7883edf3fce506df5200c0—2026-08-26
ip77.110.98.66—2026-08-26
ip185.96.80.110—2026-08-26
ip77.110.104.98—2026-08-26
ip109.120.187.217—2026-08-26
sha140d99e70de5918c6cad144dfc1ad4acd806aca3b—2026-08-26
ip176.124.220.153—2026-08-26
sha19f2be216c5df190806e621e970c9f3e106048441—2026-08-26
ip77.110.105.59—2026-08-26
sha256a2cdf2fe741de4b13ad2298b387a6c32da4a94da180ae75bf8547386aee7376b—2026-08-26
ip185.96.80.54—2026-08-26
ip46.226.162.68—2026-08-26
ip85.192.30.211—2026-08-26
ip62.60.237.22—2026-08-26
domaingestionadocs.me—2026-08-26
sha2561e499c815146124c4a6d2b48c99068b980ad74e1a2cfd16013f8d75a9425a0ca—2026-08-26
ip80.71.224.30—2026-08-26
sha256c9da1b08a39491dfdbede6ff4c1a2d383f57cb29e2d3532aee08d6e0a5c1dda6—2026-08-26
ip138.124.14.130—2026-08-26
ip193.233.245.45—2026-08-26
ip138.124.112.213—2026-08-26
domainsoportedigital.cloud—2026-08-26
ip45.152.198.108—2026-08-26
ip77.110.105.56—2026-08-26
ip79.137.192.38—2026-08-26
domaingetpdf.digital—2026-08-26
sha2560a6da70548f14834acb8960689a589b48ff422f8385ae445a281aab77045fe22—2026-08-26
📰 Threat Intel Coverage0
Digest reports mentioning this actor (incl. aliases)
No threat intel digest coverage found.