Volatile Cedar

Volatile Cedar is a Lebanese threat group that has targeted individuals, companies, and institutions worldwide. Volatile Cedar has been operating since 2012 and is motivated by political and ideological interests.[1][2]

ID: G0123
Associated Groups: Lebanese Cedar
Version: 1.1
Created: 08 February 2021
Last Modified: 20 April 2022

Associated Group Descriptions

Name Description
Lebanese Cedar

[2]

Techniques Used

Domain ID Name Use
Enterprise T1595 .002 主动扫描: Vulnerability Scanning

Volatile Cedar has performed vulnerability scans of the target server.[1][2]

.003 主动扫描: Wordlist Scanning

Volatile Cedar has used DirBuster and GoBuster to brute force web directories and DNS subdomains.[2]

Enterprise T1190 利用公开应用程序漏洞

Volatile Cedar has targeted publicly facing web servers, with both automatic and manual vulnerability discovery.[1] [2]

Enterprise T1505 .003 服务器软件组件: Web Shell

Volatile Cedar can inject web shell code into a server.[1][2]

Enterprise T1105 输入工具传输

Volatile Cedar can deploy additional tools.[2]

Software

References