← Terug naar overzicht

Arctic Wolf, with medium confidence, linked threat actors to Dark Caracal in a June 2026 intrusion targeting an unnamed communications organization in Venezuela. The attackers deployed GoCaracal, a previously undocumented Go-based malware framework. GoCaracal leverages Ethereum smart contracts to fetch replacement C2 addresses, providing resilience against takedowns. The malware grants operators remote shell access and payload execution capabilities. An extended profile adds browser data theft, keylogging, and remote desktop control. This represents a novel use of blockchain technology to maintain C2 infrastructure. The target being a communications organization raises concerns about potential intelligence collection. The use of Go and blockchain-based C2 reflects increasing sophistication in malware development.

Affected products

  • Communications organizations

Related threat actors

  • Dark Caracal

Categories

  • Emerging Technologies
  • Network Infrastructure
  • Ransomware & Malware