SYMBOLCOMMON_NAMEaka. SYNONYMS

Karkadann  (Back to overview)

aka: Piwiks

Karkadann is a threat actor that has been active since at least October 2020, targeting government bodies and news outlets in the Middle East. They have been involved in watering hole attacks, compromising high-profile websites to inject malicious JavaScript code. The group has been linked to another commercial spyware company called Candiru, suggesting they may utilize multiple spyware technologies. There are similarities in the infrastructure and tactics used by Karkadann in their campaigns.


Associated Families

There are currently no families associated with this actor.


References
2022-07-28Kaspersky LabsGReAT
APT trends report Q2 2022
Karkadann
2021-11-16ESET ResearchMatthieu Faou
Strategic web compromises in the Middle East with a pinch of Candiru
Caramel Tsunami Karkadann

Credits: MISP Project