A newly identified malware framework, termed GoCaracal, has been deployed by threat actors linked to the Dark Caracal group, according to cybersecurity firm Arctic Wolf. The intrusion, which took place in June 2026, targeted a communications company in Venezuela. GoCaracal is distinguished by its novel use of Ethereum smart contracts to update its command-and-control (C2) address.
Features and Capabilities of GoCaracal
GoCaracal empowers its operators with remote shell access and the capability to execute various payloads. Its extended version includes functionalities such as data theft from browsers, keylogging, remote desktop control, and SOCKS5 proxying. These features make the malware a versatile tool for cybercriminals.
Arctic Wolf has provided a YARA rule and several indicators of compromise (IoCs) to aid cybersecurity professionals in detecting this malware. Their analysis suggests a medium confidence link to Dark Caracal, based on various factors including the use of Bandook malware and targeting patterns specific to Latin America.
Technical Analysis and Deployment
In their detailed examination, Arctic Wolf identified two profiles of GoCaracal: a lightweight version used alongside Bandook, and an extended profile with enhanced capabilities. Despite the deployment of both profiles, there is no evidence indicating that GoCaracal is intended to replace Bandook.
The lightweight profile facilitates host profiling and encrypted C2 communication, while the extended profile includes additional features like file discovery and browser interaction. Both profiles indicate a sophisticated approach to maintaining persistence and executing commands on compromised systems.
Ethereum Integration for C2 Updates
A notable feature of GoCaracal is its method of updating its C2 address. In case the primary C2 server is unreachable, the malware sends a request to a public Ethereum JSON-RPC endpoint. The response provides a new address, which is stored in its configuration, allowing it to resume communication. This innovative use of Ethereum smart contracts allows operators to modify the C2 address without issuing a new malware version.
Arctic Wolf’s report does not confirm if this fallback mechanism was successfully executed during the June intrusion. However, the use of multiple public RPC endpoints offers resilience, minimizing the risk of losing control over infected devices.
Regional Impact and Broader Implications
While Dark Caracal is known for its operations across Latin America, Arctic Wolf’s assessment identifies potential links to activities in several countries, including Brazil, Ecuador, and Chile. However, these are not confirmed victim locations. The scale of GoCaracal’s impact remains unquantified, as Arctic Wolf has yet to disclose the full extent of organizations compromised.
The findings highlight the evolving tactics of cyber attackers and the need for robust defense mechanisms. Arctic Wolf has yet to comment on further specifics regarding the observed use of Ethereum for fallback operations.
For those seeking further details, Arctic Wolf has shared several IoCs, including SHA-256 hashes and Ethereum contract indicators, to assist organizations in defending against this threat.
