Dark Caracal Leverages GoCaracal Malware with Ethereum-Based C2 in Venezuela
The cyberespionage group Dark Caracal has been linked to a new Go-based malware framework, named GoCaracal, used in a targeted intrusion against a communications organization in Venezuela.
Arctic Wolf Labs uncovered the activity, which shows that Dark Caracal is updating its operations across Latin America while retaining familiar phishing and malware-delivery methods.
The group previously used financial-themed phishing emails, malicious SVG attachments, URL-shortening services, and a Delphi loader to target Spanish-speaking victims. The latest activity continues this approach but introduces GoCaracal alongside an updated version of the Bandook remote-access trojan.
GoCaracal has two main build profiles: a lightweight version for initial access and payload delivery, and an extended version for long-term control and intelligence collection.