Skip to content
Breaking
Mitsubishi Triton Single Cab Now Available With Automatic Transmission, Priced at RM107,980Zetrix AI plunges 50% in heavy trade, hits limit-downJakarta stocks rise as political risks ease, BI leadership takes shapeTNB and Petronas launch RM10 billion green energy partnershipSaravanan admits to taking almost RM1.1 million in bribesKak Kay’s personality framework helps couples decode relationship conflictsNepal floods trap 55 Malaysians, including two senior rescue officersSaravanan charged with receiving RM1.097m bribe, foreign worker quota application approvedJakarta protests force road closures, leaving Malaysians strandedNepal police release names of 23 missing Malaysians after floodsMerdeka Weekend, Sorted: Party, Chill & Everything In BetweenViu Original 'Cela' hits No 1 on Viu charts in first weekWhat to expect on Bursa Malaysia this FridaySaravanan arrives at court, faces corruption chargesCarbon market framework to unlock RM560 million a year in climate financeU.S.-Canada trade talks collapse as Trump prepares 50% tariffs on autos and steelIran war at six months leaves Strait of Hormuz disrupted and U.S. facing strategic setbackMistrust threatens Bersatu-PH pact for Melaka pollsKennedy Center board’s Trump renaming rush questioned by US judgeUN condemns US labeling Palestine Action as extremist groupMitsubishi Triton Single Cab Now Available With Automatic Transmission, Priced at RM107,980Zetrix AI plunges 50% in heavy trade, hits limit-downJakarta stocks rise as political risks ease, BI leadership takes shapeTNB and Petronas launch RM10 billion green energy partnershipSaravanan admits to taking almost RM1.1 million in bribesKak Kay’s personality framework helps couples decode relationship conflictsNepal floods trap 55 Malaysians, including two senior rescue officersSaravanan charged with receiving RM1.097m bribe, foreign worker quota application approvedJakarta protests force road closures, leaving Malaysians strandedNepal police release names of 23 missing Malaysians after floodsMerdeka Weekend, Sorted: Party, Chill & Everything In BetweenViu Original 'Cela' hits No 1 on Viu charts in first weekWhat to expect on Bursa Malaysia this FridaySaravanan arrives at court, faces corruption chargesCarbon market framework to unlock RM560 million a year in climate financeU.S.-Canada trade talks collapse as Trump prepares 50% tariffs on autos and steelIran war at six months leaves Strait of Hormuz disrupted and U.S. facing strategic setbackMistrust threatens Bersatu-PH pact for Melaka pollsKennedy Center board’s Trump renaming rush questioned by US judgeUN condemns US labeling Palestine Action as extremist group
AI Edge

Cybersecurity firm Arctic Wolf links new GoCaracal malware to Dark Caracal

A previously undocumented Go-based malware framework called GoCaracal was deployed during a June 2026 intrusion at a Venezuelan communications organisation, Arctic Wolf said.

Source: The Hacker News · August 27, 2026 at 10:31 AM · AI-assisted report

Single-source
Cybersecurity firm Arctic Wolf links new GoCaracal malware to Dark Caracal
Photo: GerifalteDelSabana / CC BY-SA 4.0

KUALA LUMPUR, 27 AUGUST 2026 —

Listen to this article

DomainFork Audio · read aloud

Share

A previously undocumented Go-based malware framework called GoCaracal was deployed during a June 2026 intrusion at a Venezuelan communications organisation, Arctic Wolf said.

Market Impact

The malware provides operators with remote shell access and payload execution, while an extended profile adds browser data theft, keylogging, remote desktop control and SOCKS5 proxying, according to Arctic Wolf’s technical analysis.

“We assess with medium confidence that this activity is linked to Dark Caracal,” Arctic Wolf said, citing Bandook use, recurring Delphi-loader characteristics, Spanish-language financial lures and Latin American targeting.

The lightweight profile supports host profiling, encrypted C2 channels, interactive shell access and payload retrieval, while the extended profile adds system discovery, cookie theft, keylogging, file search, WebRTC remote desktop and SOCKS5 proxying.

Arctic Wolf believes phishing delivered the malware, based on financial and tax-themed artifact naming and more than 100 related SVG files tied to the same malicious hosting site.

A novel feature is the use of an Ethereum smart contract to fetch a replacement C2 address. If the primary server fails repeatedly, GoCaracal queries a public JSON-RPC endpoint with an eth_getStorageAt call.

The response contains a replacement address stored in a configured smart contract. GoCaracal writes that address to its in-memory configuration and retries C2 communication using the new endpoint.

Multiple public RPC endpoints can read the same contract state, reducing dependence on a single fallback point. “This mechanism does not place the malware’s full command-and-control channel on Ethereum,” Arctic Wolf said.

The smart-contract method lets operators change the replacement C2 address without shipping a new binary.

Arctic Wolf disclosed the intrusion at a single Venezuelan communications organisation and did not provide a broader confirmed count of GoCaracal victims. The firm also did not confirm whether the Ethereum fallback mechanism successfully reconnected an infected host.

Dark Caracal has operated in Latin America since at least 2018. Arctic Wolf associates related artifacts and infrastructure with Brazil, Ecuador, Chile, Colombia, El Salvador and Uruguay, assessing broader regional activity with moderate confidence.

The public report provides indicators of compromise and a YARA rule for defenders. Arctic Wolf told The Hacker News it would share the full set of IOCs with customers.

Related: Kuala Lumpur

Reporting based on The Hacker News. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.