Dark Caracal Wields New Malware with Ethereum-Based C2 Fallback in Venezuela
Dark Caracal, a Lebanon-linked espionage group, has deployed new malware called GoCaracal to target communications organizations in Venezuela. This is not an isolated incident, as Dark Caracal has been linked to numerous campaigns targeting entities in various countries including Singapore, Cyprus, Chile, Italy, the USA, Turkey, Switzerland, Indonesia, and Germany.
The researchers at Arctic Wolf Labs discovered that the group used phishing emails with financial or tax lures to drop weaponized SVG attachments. When opened, these attachments redirect victims through URL shorteners to attacker-controlled sites that serve the real payload. The initial implant is not the endgame but rather establishes a foothold and pulls in a Delphi loader carrying Bandook and a more capable extended GoCaracal build.
GoCaracal has two profiles: a lightweight implant designed for access and delivering additional payloads, and an extended build intended for sustained intelligence collection and interactive control. The extended build also supports an Ethereum-based C2 fallback that allows operators to retrieve replacement command-and-control infrastructure without redeploying the malware.