logo

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

ID: e52610b2-32f9-53cd-942d-972bd56b5f33

STIX ID: report--e52610b2-32f9-53cd-942d-972bd56b5f33

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-08-27

Date Updated: 2026-08-27

Author: [email protected] (The Hacker News)

...
...

Arctic Wolf attributes a June 2026 intrusion at an unnamed Venezuelan communications organization to actors linked to Dark Caracal, reporting a new Go-based malware family called GoCaracal that provides remote shell access and payload execution in a lightweight profile and browser-data theft, keylogging, remote desktop control, SOCKS5 proxying and persistence in an extended profile; the report documents phishing-based delivery, an unusual Ethereum smart-contract fallback mechanism for C2, concurrent Bandook usage, and publishes a YARA rule and representative IoCs to aid defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.