Volatile Cedar
Also known as: Lebanese Cedar
Overview
Volatile Cedar is a Lebanese threat group that has targeted individuals, companies, and institutions worldwide. Volatile Cedar has been operating since 2012 and is motivated by political and ideological interests.
Naming & attribution
Volatile Cedar is tracked under 2 names across the industry. It uses 5 documented ATT&CK techniques — more than 13% of the 174 groups tracked here. Activity attributed since 2012.
| Name | First reported by |
|---|---|
| Lebanese Cedar | ClearSky Cyber Security |
| Volatile Cedar | Threat Intelligence and Research |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1595.003Wordlist Scanning — used by 2 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Moses Staff Iran — 3 shared techniques (21% overlap)
- BackdoorDiplomacy — 3 shared techniques (18% overlap)
- Winter Vivern Russia — 3 shared techniques (10% overlap)
- GALLIUM China — 3 shared techniques (9% overlap)
- Leviathan China — 4 shared techniques (8% overlap)
- Dragonfly Russia — 4 shared techniques (7% overlap)
Capabilities
- Exploitation of public-facing / client applications — ATT&CK T1190
TTPs — 5 techniques across 4 tactics
Reconnaissance
-
T1595.002Vulnerability Scanning -
T1595.003Wordlist Scanning
Initial Access
Persistence
-
T1505.003Web Shell
Command and Control
-
T1105Ingress Tool Transfer
Tools & malware (2)
Caterpillar WebShell · Explosive
Reporting (2)
- “Lebanese Cedar” APT Global Lebanese Espionage Campaign Leveraging Web Servers — ClearSky Cyber Security
- VOLATILE CEDAR — Threat Intelligence and Research