Volatile Cedar
1 incidentes
1 paises
0 sectores
apt LB Ultimo: 2026-05-25
Aliases: DeftTorero, Lebanese Cedar, Caterpillar 2 o Explosive, redes internas
Volatile Cedar, also known as Lebanese Cedar and DeftTorero, is a cyber espionage threat actor group with suspected ties to the Lebanese government or a political group, potentially Hezbollah. First identified in 2015 by Check Point and Kaspersky, the group has been active since 2012, conducting operations driven by political and ideological interests rather than financial gain. Volatile Cedar distinguishes itself through its highly targeted, evasive, and meticulously managed campaigns. They employ custom-developed malware, notably the 'Explosive' Remote Access Trojan, which they are the only known threat actor to use, and a specialized 'Caterpillar' WebShell. Their operations involve creating tailored malware versions for specific targets and implementing periods of inactivity to evade detection. The group's methodology focuses on sustained data collection and intelligence gathering from compromised entities globally.