logo

Dark Caracal Reloaded: New Malware, Same Hunting Grounds

ID: 1cd4ec81-61a7-5f5a-b377-1288b16780a8

STIX ID: report--1cd4ec81-61a7-5f5a-b377-1288b16780a8

Feed Name: Arctic Wolf

Threat Score
88/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: Arctic Wolf Labs

...
...

Arctic Wolf Labs attributes a June 2026 intrusion affecting a Venezuelan communications organization to Dark Caracal (medium confidence), revealing a new modular Go-based framework called GoCaracal (lightweight access and extended RAT builds) used alongside an updated Bandook; the extended build supports an Ethereum smart-contract fallback for resilient C2. The report analyzes 249 samples, describes delivery via weaponized SVG phishing and a Delphi loader, catalogs IOCs (file hashes, domains, IPs, Ethereum contracts, file paths), outlines functionality (host profiling, credential/browser theft, keylogging, WebRTC remote desktop, SOCKS5 proxy, persistence), and provides YARA rules and detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.