Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback
9 Articles
9 Articles
A new malware framework in two different versions and an evasive mechanism via the Ethereum blockchain: Arctic Wolf Labs has discovered the previously undocumented malware GoCaracal when investigating a targeted attack on an organization from the communications sector in Venezuela. Arctic Wolf assigns the attack with medium security to the cyberspionage group Dark Caracal. The most important findings from the analysis: A new modular malware fram…
Dark Caracal Hackers Use Ethereum Blockchain to Keep New Malware Connected After C2 Disruption
Dark Caracal has returned with a new tool that helps attackers stay connected when defenders shut down their control servers. The cyberespionage group is linked by researchers to a Venezuelan communications organization intrusion, where it deployed an unfamiliar Go-based malware framework called GoCaracal alongside its long-used Bandook backdoor. The campaign begins with Spanish-language financial and tax lures sent through phishing emails. Weap…
Dark Caracal deploys a new type of Go malware, equipped with an Ethereum-based C2 backup mechanism.
Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback
Dark Caracal targets Venezuela with GoCaracal, an upgraded Bandook toolkit and an Ethereum fallback for resilient C2 communications. Dark Caracal is back with new malware and the same hunting grounds. Arctic Wolf Labs researchers link a June 2026 intrusion against a communications organisation in Venezuela to the Lebanon‑linked espionage group, and says it deployed a […] This article has been indexed from Security Affairs Read the original arti…
GoCaracal malware represents a new step in the evolution of threats directed to Latin America. Discovered by Arctic Wolf Labs during an intrusion investigation against a communications organization in Venezuela, the framework combines traditional remote access capabilities with an unusual technique: using blockchain Ethereum as a contingency source to discover new addresses of command and control servers (C2). The case draws attention to why it …
Dark Caracal's New Malware GoCaracal: From SVG Phishing to Ethereum Backup C2
1. Basic Information Article Title: Dark Caracal Reloaded: New Malware, Same Hunting Grounds Publisher: Arctic Wolf Labs Publication Date: 2026-08-26 Source: Arctic Wolf Labs Related Sources: Dark Reading, Kaspersky Dark Caracal campaign report Related Malware, Threat Groups, CVEs, Products: GoCaracal, Bandook, AsioGate, Dark Caracal, Microsoft Windows, Ethereum JSON-RPC Severity: High 2. Executive Summary Dark Caracal delivers a lightwei…
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
Factuality
To view factuality data please Upgrade to Premium








