GoCaracal Malware Exploits Ethereum Blockchain for Enhanced Resilience
The GoCaracal malware framework has been discovered to use the Ethereum blockchain as part of its attack strategy. In June 2026, an attack on a Venezuelan communications firm revealed that GoCaracal can leverage the Ethereum blockchain to store backup command-and-control server addresses.
This enables attackers to maintain control even if their primary servers are unreachable. The malware can execute various malicious actions, including remote shell access and data theft.
GoCaracal retrieves updated server information by querying Ethereum smart contracts via public endpoints, without requiring new software versions. This enhances its resilience and ability to adapt to changing circumstances.