Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback
ID: 084e4db8-8563-5b03-a528-5edc6261e80f
STIX ID: report--084e4db8-8563-5b03-a528-5edc6261e80f
Feed Name: Security Affairs
Arctic Wolf links a June 2026 intrusion against a Venezuelan communications organization to the Lebanon‑associated APT Dark Caracal, which deployed a new Go-based implant (GoCaracal) alongside an updated Bandook backdoor. The campaign used phishing with weaponized SVGs to deliver a lightweight Go implant that fetched a Delphi loader installing Bandook and an extended GoCaracal build; the extended build adds broad intelligence-collection features and an Ethereum smart-contract fallback to dynamically provide replacement C2 addresses, with 249 related samples and multi-country Latin American targeting observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
