logo

Dark Caracal group might have refreshed its malware, researchers say

ID: 520c4e7b-8063-540a-82cb-17f11baae1d3

STIX ID: report--520c4e7b-8063-540a-82cb-17f11baae1d3

Feed Name: The Record from Recorded Future News

Threat Score
70/100

Date Published: 2025-03-04

Date Updated: 2026-05-01

...
...

Dark Caracal is reportedly shifting from Bandook to Poco RAT in an espionage and financially-motivated phishing campaign across Latin America, with researchers detecting 483 Poco RAT samples between June 2024 and February; victims in Venezuela, the Dominican Republic and Chile received invoice-themed phishing attachments that redirected to legitimate cloud storage to deliver a credential-harvesting RAT capable of spying, executing commands and loading additional malware. The campaign reuses Bandook-like TTPs—blurred decoy documents, link shorteners and cloud-hosted payloads—indicating the group may be replacing older tooling while maintaining consistent operational methodology and mixed espionage/financial objectives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.