ATT&CKGroupsVolatile Cedar

Volatile Cedar

G0123

Threat group.View on attack.mitre.org

About this group

Volatile Cedar is a Lebanese threat group that has targeted individuals, companies, and institutions worldwide. Volatile Cedar has been operating since 2012 and is motivated by political and ideological interests.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1105
Ingress Tool Transfer

Volatile Cedar can deploy additional tools.

T1190
Exploit Public-Facing Application

Volatile Cedar has targeted publicly facing web servers, with both automatic and manual vulnerability discovery.

T1505.003
Web Shell

Volatile Cedar can inject web shell code into a server.

T1595.002
Vulnerability Scanning

Volatile Cedar has performed vulnerability scans of the target server.

T1595.003
Wordlist Scanning

Volatile Cedar has used DirBuster and GoBuster to brute force web directories and DNS subdomains.

Software2

Campaigns0

None recorded.

References2

  1. CheckPoint Volatile Cedar March 2015 Open source
    Threat Intelligence and Research. (2015, March 30). VOLATILE CEDAR. Retrieved February 8, 2021.
  2. ClearSky Lebanese Cedar Jan 2021 Open source
    ClearSky Cyber Security. (2021, January). “Lebanese Cedar” APT Global Lebanese Espionage Campaign Leveraging Web Servers. Retrieved February 10, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.