GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
-
Arctic Wolf researchers have linked a new malware framework to the threat actor known as Dark Caracal, with medium confidence, following an intrusion detected in June 2026 at an unnamed communications organization in Venezuela. The tool, dubbed GoCaracal, is a previously undocumented, Go-based malware framework deployed during the attack.
GoCaracal grants operators remote shell access and the ability to execute payloads on compromised hosts. An extended version of the framework also includes modules for browser data theft, keylogging, and remote desktop control, giving attackers broad surveillance and takeover capabilities over infected systems.
One of the more distinctive features of this malware is its use of the Ethereum blockchain for command-and-control resilience. GoCaracal is designed to fetch replacement C2 addresses via an Ethereum smart contract, making it more difficult for defenders to block or takedown infrastructure using traditional domain or IP-based denylisting.
Key technical details reported include:
- Written in Go, compiled as a single binary.
- Provides remote shell and arbitrary payload execution.
- Extended variant includes browser credential theft, keylogging, and remote desktop functions.
- Uses Ethereum smart contracts to resolve new C2 server addresses.
- Attribution to Dark Caracal is assessed as medium confidence by Arctic Wolf.
Source: The Hacker News
Are you seeing any novel C2 techniques like blockchain-based resolution in your threat intelligence feeds, and how are you adapting your detection to account for them?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login