GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

Read full story on The Hacker News
Share
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
AI disclosure

Summary

Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela. GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds browser data theft, keylogging, remote desktop control

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.