importantSYS.SOURCE: The Hacker News• 2026-08-27T15:03:38+05:30
GoCaracal Malware Leverages Ethereum Smart Contracts for Dynamic C2 Address Replacement
GoCaracal malware employs Ethereum smart contracts to dynamically retrieve replacement command-and-control (C2) addresses, evading traditional detection methods. Arctic Wolf links the malware to Dark Caracal with medium confidence, noting its use of phishing and advanced persistence techniques.
Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela.
GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds browser data theft, keylogging, remote desktop control
*** END OF TRANSMISSION ***