logo

Dark Caracal Expands Cyber Espionage with GoCaracal Malware Framework

ID: 37a54172-c663-5940-96e4-248a65ff4f13

STIX ID: report--37a54172-c663-5940-96e4-248a65ff4f13

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-08-26

Date Updated: 2026-08-27

...
...

Dark Caracal has introduced a new malware framework named GoCaracal consisting of a lightweight initial-access implant and a more capable intelligence-gathering variant that can use an Ethereum blockchain database for backup command-and-control. Discovered by Arctic Wolf in an investigation in Venezuela, the activity is linked to ongoing Spanish-language phishing campaigns targeting military, government, and other organizations across Latin America, suggesting a sophisticated and persistent cyberespionage capability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.