Cybersecurity firm Arctic Wolf links new GoCaracal malware to Dark Caracal
A previously undocumented Go-based malware framework called GoCaracal was deployed during a June 2026 intrusion at a Venezuelan communications organisation, Arctic Wolf said.
Source: The Hacker News · August 27, 2026 at 10:31 AM · AI-assisted report
Single-sourceKUALA LUMPUR, 27 AUGUST 2026 —
A previously undocumented Go-based malware framework called GoCaracal was deployed during a June 2026 intrusion at a Venezuelan communications organisation, Arctic Wolf said.
Market Impact
The malware provides operators with remote shell access and payload execution, while an extended profile adds browser data theft, keylogging, remote desktop control and SOCKS5 proxying, according to Arctic Wolf’s technical analysis.
“We assess with medium confidence that this activity is linked to Dark Caracal,” Arctic Wolf said, citing Bandook use, recurring Delphi-loader characteristics, Spanish-language financial lures and Latin American targeting.
The lightweight profile supports host profiling, encrypted C2 channels, interactive shell access and payload retrieval, while the extended profile adds system discovery, cookie theft, keylogging, file search, WebRTC remote desktop and SOCKS5 proxying.
Arctic Wolf believes phishing delivered the malware, based on financial and tax-themed artifact naming and more than 100 related SVG files tied to the same malicious hosting site.
A novel feature is the use of an Ethereum smart contract to fetch a replacement C2 address. If the primary server fails repeatedly, GoCaracal queries a public JSON-RPC endpoint with an eth_getStorageAt call.
The response contains a replacement address stored in a configured smart contract. GoCaracal writes that address to its in-memory configuration and retries C2 communication using the new endpoint.
Multiple public RPC endpoints can read the same contract state, reducing dependence on a single fallback point. “This mechanism does not place the malware’s full command-and-control channel on Ethereum,” Arctic Wolf said.
The smart-contract method lets operators change the replacement C2 address without shipping a new binary.
Arctic Wolf disclosed the intrusion at a single Venezuelan communications organisation and did not provide a broader confirmed count of GoCaracal victims. The firm also did not confirm whether the Ethereum fallback mechanism successfully reconnected an infected host.
Dark Caracal has operated in Latin America since at least 2018. Arctic Wolf associates related artifacts and infrastructure with Brazil, Ecuador, Chile, Colombia, El Salvador and Uruguay, assessing broader regional activity with moderate confidence.
The public report provides indicators of compromise and a YARA rule for defenders. Arctic Wolf told The Hacker News it would share the full set of IOCs with customers.
Related: Kuala Lumpur