<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address]]></title><description><![CDATA[<p dir="auto">Arctic Wolf researchers have linked a new malware framework to the threat actor known as Dark Caracal, with medium confidence, following an intrusion detected in June 2026 at an unnamed communications organization in Venezuela. The tool, dubbed <strong>GoCaracal</strong>, is a previously undocumented, Go-based malware framework deployed during the attack.</p>
<p dir="auto">GoCaracal grants operators remote shell access and the ability to execute payloads on compromised hosts. An extended version of the framework also includes modules for browser data theft, keylogging, and remote desktop control, giving attackers broad surveillance and takeover capabilities over infected systems.</p>
<p dir="auto">One of the more distinctive features of this malware is its use of the Ethereum blockchain for command-and-control resilience. GoCaracal is designed to fetch replacement C2 addresses via an Ethereum smart contract, making it more difficult for defenders to block or takedown infrastructure using traditional domain or IP-based denylisting.</p>
<p dir="auto">Key technical details reported include:</p>
<ul>
<li>Written in Go, compiled as a single binary.</li>
<li>Provides remote shell and arbitrary payload execution.</li>
<li>Extended variant includes browser credential theft, keylogging, and remote desktop functions.</li>
<li>Uses Ethereum smart contracts to resolve new C2 server addresses.</li>
<li>Attribution to Dark Caracal is assessed as medium confidence by Arctic Wolf.</li>
</ul>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/08/gocaracal-malware-uses-ethereum-smart.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto"><em>Are you seeing any novel C2 techniques like blockchain-based resolution in your threat intelligence feeds, and how are you adapting your detection to account for them?</em></p>
]]></description><link>https://xploitlk.com/topic/158/gocaracal-malware-uses-ethereum-smart-contract-to-fetch-replacement-c2-address</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 15:05:38 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/158.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 30 Aug 2026 20:30:23 GMT</pubDate><ttl>60</ttl></channel></rss>