Dark Caracal Leverages Ethereum Blockchain for Resilient Malware Operations
The cyberespionage group Dark Caracal has returned with a new tool that helps attackers stay connected when defenders shut down their control servers. This new framework, called GoCaracal, uses the Ethereum blockchain to provide a fallback connection in case the main server is disrupted.
Researchers at Arctic Wolf identified GoCaracal while investigating the June 2026 breach of a Venezuelan communications organization. They found that the group deployed an unfamiliar Go-based malware framework alongside its long-used Bandook backdoor.
The campaign begins with Spanish-language financial and tax lures sent through phishing emails, which contain shortened links and redirect recipients to payload hosting sites. The operators then provide an archive that starts a small implant and opens the door to more capable tools.
GoCaracal adds flexibility to the group's operations, making infrastructure disruption less decisive. Affected organizations may include targets across Latin America, beyond the confirmed Venezuelan incident.