Skip to content
Back to Guavy Wire
Crypto

GoCaracal Malware Framework Exploits Ethereum Infrastructure

Instruments
ETH MEW
Share

A newly documented malware framework called GoCaracal is using Ethereum infrastructure to support command-and-control recovery during cyberattacks. Arctic Wolf observed the Go-based malware during a June 2026 intrusion involving a communications organization in Venezuela.

The framework gives operators remote shell access and allows them to retrieve and execute additional payloads. Its extended version also supports browser data theft, keylogging, remote desktop control, and SOCKS5 proxy functions.

GoCaracal first attempts to communicate with a configured command-and-control server through a normal off-chain connection. When repeated attempts fail, the malware can query a public Ethereum JSON-RPC endpoint for another address.

The request uses ‘eth_getStorageAt’ to read data stored within a configured Ethereum smart contract. That response contains a replacement C2 address, which GoCaracal places into its active memory configuration.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc