Darket Diaries
Darket Diaries

38: Dark Caracal

A journalist wrote articles critical of the Kazakhstan government. The government did not like this and attempted to silence her. But they may have done more than just silence her. Perhaps they tried to spy on her too. The EFF investigated this case and went down a very interesting rabbit hole. Than

Featured Speakers

Jack Rhysider Host

Topics Discussed

Episode Summary

Executive Summary: The episode traces EFF and Lookout’s investigation into a sprawling spyware campaign that began with targeting Kazakh journalists and expanded into a global operation affecting victims in 21 countries. By analyzing malware, exposed command-and-control data, and network clues, researchers increasingly implicated cyber mercenaries linked to Lebanese government infrastructure, showing how states can outsource surveillance against dissidents, journalists, and activists.

Main Topics: Abandoned-hospital prologue and the theme of hidden watchers (Priority: 2/5): The episode opens with a creepy abandoned-hospital story to frame the central feeling of the investigation: sensing an unseen observer without proof, which mirrors the surveillance campaign later uncovered. EFF Threat Lab and the origin of Operation Manul (Priority: 5/5): Cooper Quinton explains EFF’s new Threat Lab and how the investigation began with Irina Petrushova, editor of Respublika, after she and colleagues received spear-phishing emails containing malware. Kazakhstan-linked digital espionage against journalists and activists (Priority: 5/5): The team first connects malware activity to Kazakhstan through politically targeted phishing, leaked government emails, and the targeting of people involved in disputes with the Kazakh government. Expansion from desktop malware to mobile spyware (Priority: 5/5): Researchers uncover JRAT, Bandook, and then a mobile component called Palace/Dark Caracal, revealing spyware that could steal files, record audio, capture screens, and intercept messages. From circumstantial clues to attribution via exposed infrastructure (Priority: 5/5): By scraping open directories, analyzing admin logins, Wi-Fi SSIDs, and victim metadata, the team links parts of the operation to Beirut-based Lebanese government infrastructure and intelligence facilities. Cyber mercenaries and state outsourcing of surveillance (Priority: 4/5): The discussion argues that governments like Kazakhstan and Lebanon may be buying hacking services from contractors, allowing plausible deniability while carrying out espionage against multiple targets worldwide. Impact on EFF, research methods, and broader digital rights work (Priority: 4/5): The case helps justify EFF’s Threat Lab and broader efforts against spyware and stalkerware, showing the importance of defensive research and public exposure of government-aligned cyber abuse.

Key Arguments: The initial phishing campaign was targeted, not random crimeware, because the emails were tailored to Irina and her network and deployed spyware rather than financially motivated malware. Operation Manul likely began as surveillance tied to Kazakhstan because victims were journalists, dissidents, and associates opposing or exposing the government. The malware was operationally sloppy: open directories, weak server security, reused infrastructure, and visible logs allowed researchers to access large amounts of stolen data. The campaign expanded beyond Kazakhstan to victims in Lebanon and 19 other countries, undermining the theory that it was a single-country operation and pointing toward a broader mercenary service. The strongest attribution clues came from infrastructure and behavior: admin logins from Beirut/Lebanon telecom space, Wi-Fi tied to the Lebanese General Directorate of General Security, and malware code similarities. The same developer/signature patterns across Bandook, CrossRAT, and the mobile spyware suggest shared authorship or a small common team, with Prince Ali as a key suspected figure. This case shows why cyber mercenaries are dangerous: states can outsource spying to contractors, evade responsibility, and quickly rebuild after exposure. EFF Threat Lab exists because exposing spyware campaigns requires sustained technical investigation alongside legal, journalistic, and civil-liberties work.

Data Points: Countries with victims: 21 countries - Researchers mapped infected devices across the globe, including Lebanon, Kazakhstan, the U.S., China, France, Germany, India, and others. Domains tied to the campaign: Over 20 domains - These domains were used for phishing, malware delivery, credential theft, and data exfiltration. Command-and-control servers discovered initially: 2 servers - EFF identified two C2 servers early in the investigation tied to the desktop malware operation. Desktop malware sale price: About $40 in Bitcoin - JRAT was available at jrat.io for a low price, showing the malware was commodity-grade rather than elite tooling. Data on Adobe Air.net: 81 gigabytes - Lookout and EFF found a huge volume of exfiltrated data stored on one server. Files scraped from the servers: 264,000 files - Part of the stolen material researchers were able to access from exposed directories. SMS messages scraped: 486,000 SMS messages - Large volume of stolen text communications found on attacker-controlled infrastructure. Contacts scraped: 250,000 contacts - Victims’ address books were included in the exposed data. Call records scraped: 150,000 call records - Researchers recovered extensive telephony metadata from the exfiltrated dataset. Authentication accounts: 1,000 accounts - Username/password combinations were found among the stolen information. Unique Wi-Fi SSIDs: 206,000 - The malware logged Wi-Fi networks connected to by victims, aiding location and attribution analysis. Publicly visible browser history count: 92,000,000,000,000 browsing history URLs - A quoted figure from the transcript used to emphasize the scale of captured browsing data. Leak-related victim geography: Multiple regions including Beirut downtown and Kazakhstan - Admin IPs traced to Ogero Telecom in Beirut, and test devices tied to a Wi-Fi network in the Lebanese General Security building.

Pivotal Quotes: "This is actually somebody trying to under. take digital espionage, right? This is somebody actually trying to spy on her." — Cooper Quinton: Explaining why the malware campaign against Irina was clearly targeted surveillance rather than ordinary cybercrime. "I’ve been trying to popularize the term cyber mercenaries." — Cooper Quinton: Describing actors who sell hacking and surveillance services to governments and other clients. "When you look down the long Ethernet cable into the dark, dark part of the net. The dark net sometimes looks back." — Jack Rhysider: Closing reflection on the dangers and unease of investigating hidden online surveillance.

Implications: The episode shows how cheap, sloppy spyware can still enable powerful state surveillance when outsourced to contractors. For journalists, activists, and defenders, it underscores the need for stronger mobile security, transparency, and continued independent threat research.

🔓 Sign Up for Unlimited Episode Search

About Darket Diaries

Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.

View all episodes from Darket Diaries