Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GoCaracal Malware Uses Ethereum for C2 Address Updates

GoCaracal Malware Uses Ethereum for C2 Address Updates

Posted on August 27, 2026 By CWS

A newly identified malware framework, termed GoCaracal, has been deployed by threat actors linked to the Dark Caracal group, according to cybersecurity firm Arctic Wolf. The intrusion, which took place in June 2026, targeted a communications company in Venezuela. GoCaracal is distinguished by its novel use of Ethereum smart contracts to update its command-and-control (C2) address.

Features and Capabilities of GoCaracal

GoCaracal empowers its operators with remote shell access and the capability to execute various payloads. Its extended version includes functionalities such as data theft from browsers, keylogging, remote desktop control, and SOCKS5 proxying. These features make the malware a versatile tool for cybercriminals.

Arctic Wolf has provided a YARA rule and several indicators of compromise (IoCs) to aid cybersecurity professionals in detecting this malware. Their analysis suggests a medium confidence link to Dark Caracal, based on various factors including the use of Bandook malware and targeting patterns specific to Latin America.

Technical Analysis and Deployment

In their detailed examination, Arctic Wolf identified two profiles of GoCaracal: a lightweight version used alongside Bandook, and an extended profile with enhanced capabilities. Despite the deployment of both profiles, there is no evidence indicating that GoCaracal is intended to replace Bandook.

The lightweight profile facilitates host profiling and encrypted C2 communication, while the extended profile includes additional features like file discovery and browser interaction. Both profiles indicate a sophisticated approach to maintaining persistence and executing commands on compromised systems.

Ethereum Integration for C2 Updates

A notable feature of GoCaracal is its method of updating its C2 address. In case the primary C2 server is unreachable, the malware sends a request to a public Ethereum JSON-RPC endpoint. The response provides a new address, which is stored in its configuration, allowing it to resume communication. This innovative use of Ethereum smart contracts allows operators to modify the C2 address without issuing a new malware version.

Arctic Wolf’s report does not confirm if this fallback mechanism was successfully executed during the June intrusion. However, the use of multiple public RPC endpoints offers resilience, minimizing the risk of losing control over infected devices.

Regional Impact and Broader Implications

While Dark Caracal is known for its operations across Latin America, Arctic Wolf’s assessment identifies potential links to activities in several countries, including Brazil, Ecuador, and Chile. However, these are not confirmed victim locations. The scale of GoCaracal’s impact remains unquantified, as Arctic Wolf has yet to disclose the full extent of organizations compromised.

The findings highlight the evolving tactics of cyber attackers and the need for robust defense mechanisms. Arctic Wolf has yet to comment on further specifics regarding the observed use of Ethereum for fallback operations.

For those seeking further details, Arctic Wolf has shared several IoCs, including SHA-256 hashes and Ethereum contract indicators, to assist organizations in defending against this threat.

The Hacker News Tags:Arctic Wolf, C2 address, cyber threats, Cybersecurity, Dark Caracal, Ethereum, GoCaracal, Latin America, Malware, Phishing

Post navigation

Previous Post: New Windows Backdoor SLEEPWALKER Evades Detection
Next Post: Pro-Russian Hackers Target Norway’s Digital Services

Related Posts

Chaos RaaS Emerges After BlackSuit Takedown, Demanding 0K from U.S. Victims Chaos RaaS Emerges After BlackSuit Takedown, Demanding $300K from U.S. Victims The Hacker News
Enhancing Security: The Rise of Autonomous Purple Teaming Enhancing Security: The Rise of Autonomous Purple Teaming The Hacker News
Microsoft Addresses Record 622 Vulnerabilities, Including Two Critical Zero-Days Microsoft Addresses Record 622 Vulnerabilities, Including Two Critical Zero-Days The Hacker News
Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain Attacks Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain Attacks The Hacker News
Cross-Platform QuimaRAT MaaS Targets Multiple OS Cross-Platform QuimaRAT MaaS Targets Multiple OS The Hacker News
New Linux Flaws Enable Full Root Access via PAM and Udisks Across Major Distributions New Linux Flaws Enable Full Root Access via PAM and Udisks Across Major Distributions The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Veeam ONE Flaw Risks Credential Exposure
  • Cyberattack Disrupts Boston Scientific’s Global Operations
  • AI-Powered Phishing Service Targets Stolen iPhones
  • Pro-Russian Hackers Target Norway’s Digital Services
  • GoCaracal Malware Uses Ethereum for C2 Address Updates

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Veeam ONE Flaw Risks Credential Exposure
  • Cyberattack Disrupts Boston Scientific’s Global Operations
  • AI-Powered Phishing Service Targets Stolen iPhones
  • Pro-Russian Hackers Target Norway’s Digital Services
  • GoCaracal Malware Uses Ethereum for C2 Address Updates

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark