GoCaracal Malware Uses Ethereum Smart Contract for Replacement C2 Addresses
A previously undocumented malware framework, GoCaracal, has been linked to Dark Caracal by Arctic Wolf. The framework provides remote shell access and payload execution, with an extended profile adding browser data theft, keylogging, remote desktop control, and SOCKS5 proxying.
The malware was deployed during a June 2026 intrusion at an unnamed communications organization in Venezuela. Arctic Wolf based its assessment on Bandook use, recurring Delphi-loader characteristics, Spanish-language financial lures, malicious SVGs, URL shorteners, document-themed infrastructure, hosting-provider preferences, and Latin American targeting.
The GoCaracal malware uses a novel mechanism to fetch replacement C2 addresses by sending an eth_getStorageAt request to a public Ethereum JSON-RPC endpoint. The response provides a replacement address stored in the configured smart contract, which is then written to the malware's in-memory configuration.