logo

Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback

ID: 084e4db8-8563-5b03-a528-5edc6261e80f

STIX ID: report--084e4db8-8563-5b03-a528-5edc6261e80f

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-08-27

Date Updated: 2026-08-28

Author: Pierluigi Paganini

...
...

Arctic Wolf links a June 2026 intrusion against a Venezuelan communications organization to the Lebanon‑associated APT Dark Caracal, which deployed a new Go-based implant (GoCaracal) alongside an updated Bandook backdoor. The campaign used phishing with weaponized SVGs to deliver a lightweight Go implant that fetched a Delphi loader installing Bandook and an extended GoCaracal build; the extended build adds broad intelligence-collection features and an Ethereum smart-contract fallback to dynamically provide replacement C2 addresses, with 249 related samples and multi-country Latin American targeting observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.