GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
Ağu 27, 2026
Malware / Phishing
Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal , during a June 2026 intrusion at an unnamed communications organization in Venezuela. GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds browser data theft, keylogging, remote desktop control, and SOCKS5 proxying. Arctic Wolf also published a YARA rule and representative indicators of compromise (IoCs) that defenders can use to hunt for the malware. "We assess with medium confidence that this activity is linked to Dark Caracal," Arctic Wolf said. Arctic Wolf based the assessment on Bandook use, recurring Delphi-loader characteristics, Spanish-language financial lures, malicious SVGs, URL shorteners, document-themed infrastructure, hosting-provider preferences, and Latin American targeting. In its technical analysis of GoCaracal , Arctic Wolf said the malware ap...