>samit_hota
Back to adversary profiles

Threat Actor Dossier

Volatile Cedar: Persistent Lebanese Cyber Espionage Group (G0123)

G0123

Also tracked as Lebanese Cedar · 8 sectors targeted

Threat level
HIGH
Status
ACTIVE
Origin
Lebanon
Motivation
Espionage · Political
Samit Hota·
Target Sectors
Telecommunications, Media, Education, Government, Defense Contractors, Web Hosting, Internet Service Providers, Corporate
Associated Malware
Explosive, Caterpillar WebShell, ASPXspy, Mamad Warning, DirBuster, GoBuster
#threat-actor#g0123

Overview

Volatile Cedar, also tracked as Lebanese Cedar, is a persistent threat group (MITRE ATT&CK ID G0123) that has been operating since at least late 2012. Attributed to Lebanon, with strong indications of nation-state or political group backing, including potential links to the Hezbollah Cyber Unit, the group’s activities are driven by political and ideological interests rather than financial gain. Their primary objective is information theft and espionage, meticulously collecting data from carefully chosen targets worldwide.

The group’s operational approach is characterized by its highly targeted and well-managed campaigns. They meticulously select a limited number of victims, tailoring their attacks to minimize exposure and maximize success. This discretion, coupled with their consistent operational timeline, suggests a disciplined and resourced adversary, even if their technical exploits aren’t always considered “cutting edge.” Volatile Cedar maintains continuous monitoring of their victims, promptly adapting their tactics in response to detection events.

Geographically, while Volatile Cedar has targeted individuals, companies, and institutions globally, a significant concentration of their operations has been observed across the Middle East. Specific target countries include the USA, UK, Egypt, Jordan, Lebanon, Israel, Palestinian Authority, Canada, Turkey, Russia, Saudi Arabia, UAE, and Kuwait. Their target sectors are diverse, encompassing defense contractors, telecommunications, media, educational institutions, web hosting providers, internet service providers, government entities, and other corporate targets.

Tactics & Techniques

Volatile Cedar’s initial access typically deviates from common APT methods like spear phishing. Instead, they primarily focus on publicly facing web servers, often running Windows operating systems, Oracle, or Atlassian/JIRA applications. Their attack chain often begins with extensive reconnaissance, utilizing both automated and manual vulnerability scanning to identify unpatched systems. They are known to leverage open-source tools such as Shodan, Censys, ZoomEye for network scanning and GoBuster or DirBuster for brute-forcing web directories and DNS subdomains. They exploit known vulnerabilities, including specific Oracle 10g and Atlassian (JIRA) flaws like CVE-2012-3152, often exploiting file upload forms or web application command injection vulnerabilities to gain a foothold.

Once they gain control of a server, the group injects web shells and deploys their custom Remote Access Trojan (RAT), Explosive, to establish persistence and enable lateral movement. They use the compromised servers as pivot points to explore and penetrate deeper into internal networks through various means, including manual hacking and automated USB infection mechanisms. Keylogging capabilities within their malware are employed to harvest administrator credentials, which are then used to further move laterally within the network or access other systems hosted by the same service. Their command and control (C2) infrastructure is multi-tiered, involving static and dynamic update servers, with some employing domain generation algorithms (DGA) for resilience. They also use VPN services like NordVPN and ExpressVPN to obscure their C2 communications.

Defense evasion is a core aspect of Volatile Cedar’s operations. They develop and deploy custom versions of their malware specifically for certain targets, embedding “radio silence” periods. They meticulously monitor antivirus detection results and system memory consumption, updating their tools frequently to avoid heuristic detection. In some cases, they are known to suspend external communications to remain undetected. There are suspicions that the group may have shifted towards fileless malware to further camouflage their activities.

Notable Campaigns

Volatile Cedar has a long operational history, first identified publicly in reports by Check Point and Kaspersky Labs in 2015, which detailed activity dating back to late 2012. After maintaining a relatively low profile for several years, the group resurfaced with a notable campaign in early 2020. This resurgence saw the deployment of new versions of their primary malware, Explosive (V4), and the Caterpillar WebShell (V2), targeting telecommunication companies and internet service providers across a wide geographic range including the US, UK, Middle East, and North Africa. During this campaign, ClearSky researchers identified approximately 250 servers breached through the exploitation of vulnerable Oracle and Atlassian servers using a modified JSP file browser. Further activity was observed by Kaspersky researchers in mid-2021, indicating continued operations and evolution of their tactics. Historically, the group has demonstrated an ability to react quickly to public disclosure, even activating self-destruct commands in response to shared intelligence.

Associated Malware & Tools

Volatile Cedar’s toolkit relies heavily on custom-developed malware, supplemented by readily available hacking tools. Their primary weapon is Explosive, a custom-made Remote Access Trojan (RAT). Explosive is designed for data exfiltration, employing keylogging and other data-stealing functionalities, and has shown capabilities for lateral movement and even USB infection in later versions. It is often structured as a main binary and a DLL file, allowing for rapid patching and evasion of antivirus detection.

Another significant tool in their arsenal is the Caterpillar WebShell, a custom web shell believed to be a variant of the open-source ASPXspy. This web shell provides persistent access to compromised web servers, facilitating command execution and data exfiltration to their C2 infrastructure. Other web shells, such as Mamad Warning, have also been observed.

For initial reconnaissance and vulnerability exploitation, Volatile Cedar utilizes various open-source hacking tools. These include public vulnerability scanners, custom-built port scanners, and tools like DirBuster and GoBuster for brute-forcing directories. They also employ modified JSP file browsers (e.g., test.jsp, yup.jsp) specifically tailored to deploy the Explosive RAT onto vulnerable Oracle and Atlassian servers. To further enhance their stealth and operational security, they use commercial VPN services such as NordVPN and ExpressVPN for their C2 communications.

Current Status

Volatile Cedar remains an active and persistent threat actor. Reports from early 2020 and mid-2021 confirm their ongoing campaigns, demonstrating their continued operational capability and adaptation. The group has consistently shown a capacity to evolve its malware and tactics, ensuring its campaigns remain successful despite detection efforts. Their meticulous and targeted approach allows them to operate under the radar effectively, even if their technical sophistication is not always at the bleeding edge. Given the geopolitical landscape and the group’s clear political and ideological motivations, it is highly probable that Volatile Cedar will continue its cyber espionage activities against perceived adversaries and targets of interest. The MITRE ATT&CK framework lists Volatile Cedar (G0123) with a last modification date of April 16, 2025, further reinforcing its continued relevance and active status.

Worried this actor targets your sector?

Let's map your exposure before they find it themselves.

Book an advisory call