Dark Caracal group might have refreshed its malware, researchers say
ID: 520c4e7b-8063-540a-82cb-17f11baae1d3
STIX ID: report--520c4e7b-8063-540a-82cb-17f11baae1d3
Feed Name: The Record from Recorded Future News
Dark Caracal is reportedly shifting from Bandook to Poco RAT in an espionage and financially-motivated phishing campaign across Latin America, with researchers detecting 483 Poco RAT samples between June 2024 and February; victims in Venezuela, the Dominican Republic and Chile received invoice-themed phishing attachments that redirected to legitimate cloud storage to deliver a credential-harvesting RAT capable of spying, executing commands and loading additional malware. The campaign reuses Bandook-like TTPs—blurred decoy documents, link shorteners and cloud-hosted payloads—indicating the group may be replacing older tooling while maintaining consistent operational methodology and mixed espionage/financial objectives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
