GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
ID: e52610b2-32f9-53cd-942d-972bd56b5f33
STIX ID: report--e52610b2-32f9-53cd-942d-972bd56b5f33
Feed Name: The Hacker News
Arctic Wolf attributes a June 2026 intrusion at an unnamed Venezuelan communications organization to actors linked to Dark Caracal, reporting a new Go-based malware family called GoCaracal that provides remote shell access and payload execution in a lightweight profile and browser-data theft, keylogging, remote desktop control, SOCKS5 proxying and persistence in an extended profile; the report documents phishing-based delivery, an unusual Ethereum smart-contract fallback mechanism for C2, concurrent Bandook usage, and publishes a YARA rule and representative IoCs to aid defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
