Back to Feed
MalwareAug 27, 2026

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

GoCaracal malware uses Ethereum smart contracts for C2 fallback.

Summary

A new Go-based malware framework named GoCaracal has been deployed by threat actors potentially linked to Dark Caracal. The malware offers remote shell access, payload execution, and extended features like keylogging and browser data theft. Notably, GoCaracal utilizes an Ethereum smart contract to dynamically fetch replacement C2 addresses when primary servers fail, allowing operators to update C2 infrastructure without distributing new binaries.

Full text

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address Swati KhandelwalAug 27, 2026Malware / Phishing Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela. GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds browser data theft, keylogging, remote desktop control, and SOCKS5 proxying. Arctic Wolf also published a YARA rule and representative indicators of compromise (IoCs) that defenders can use to hunt for the malware. "We assess with medium confidence that this activity is linked to Dark Caracal," Arctic Wolf said. Arctic Wolf based the assessment on Bandook use, recurring Delphi-loader characteristics, Spanish-language financial lures, malicious SVGs, URL shorteners, document-themed infrastructure, hosting-provider preferences, and Latin American targeting. In its technical analysis of GoCaracal, Arctic Wolf said the malware appeared in lightweight and extended profiles during the investigated intrusion. Bandook was subsequently deployed alongside the lightweight profile. It was used in parallel with GoCaracal, and Arctic Wolf said current evidence does not establish GoCaracal as a replacement for Bandook. The lightweight profile supports host profiling, an encrypted command-and-control (C2) channel, interactive shell access, payload retrieval and execution, and shellcode loading and injection. The extended profile adds system and file discovery, command execution, browser cookie and login-database collection, keylogging, targeted file search, Web Real-Time Communication (WebRTC) remote desktop, hidden browser interaction, SOCKS5 proxying, and persistence-related functionality. Arctic Wolf assesses phishing as the delivery mechanism, although it did not recover the original phishing email or Scalable Vector Graphics (SVG) attachment from the victim. The firm based that assessment on financial and tax-themed artifact naming, the established campaign pattern, and more than 100 related SVG files that communicated with the same malicious hosting site. The extended GoCaracal profile first attempts to communicate with its configured primary C2 server. After repeated failures, it sends an eth_getStorageAt request to a public Ethereum JSON-RPC endpoint. The response provides a replacement address stored in the configured smart contract. GoCaracal writes that address to its in-memory configuration. It then retries conventional off-chain C2 communication using the replacement address. Multiple public RPC endpoints can be used to read the same contract state, reducing dependence on a single fallback access point. "This mechanism does not place the malware’s full command-and-control channel on Ethereum," Arctic Wolf said. The smart-contract mechanism lets the operator change the replacement C2 address without shipping a new GoCaracal binary. Arctic Wolf's public report does not show a host in the June intrusion that invoked the fallback and successfully reconnected through the replacement address. Dark Caracal has a documented history of operating in Latin America. The Hacker News covered the original Dark Caracal disclosure in 2018, followed by retooled Bandook malware in 2020 and Bandook attacks in Venezuela in 2021. Arctic Wolf said related artifacts and infrastructure were associated with Brazil, Ecuador, Chile, Colombia, El Salvador, and Uruguay, assessing that broader regional activity with moderate confidence. Arctic Wolf does not identify those locations as confirmed victim countries. The public report provides no broader confirmed count of organizations compromised with GoCaracal. The Hacker News contacted Arctic Wolf for clarification on whether the Ethereum fallback was observed executing on an infected host and on the confirmed scope of the campaign; Arctic Wolf had not responded at the time of publication. Arctic Wolf shared the following indicators of compromise (IoCs) - A YARA rule for the lightweight GoCaracal profile. Representative SHA-256 hashes and related domains and IP addresses. Ethereum contract and wallet indicators. Host paths associated with the malware. The company said the public indicators are referential and that the full set is available to Arctic Wolf customers. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Malware, Phishing ⚡ Top Stories This Week Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE Attackers Exploit SharePoint Authentication Bypass After Public PoC Release Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access ⭐ Featured Resources See How Keeper Secrets Manager Removes Hard-Coded Credentials Download the CISO's Guide to Smarter AI Security Investment Phishing Is Costing Security Teams More Than Ever — Read the New Report Build AI Agents and Automations Without Losing Security Control

Indicators of Compromise

  • mitre_attack — T1059.001
  • mitre_attack — T1105
  • mitre_attack — T1071.001
  • mitre_attack — T1055
  • mitre_attack — T1056.001
  • mitre_attack — T1537
  • mitre_attack — T1219
  • mitre_attack — T1090.003
  • mitre_attack — T1078.004
  • mitre_attack — T1071.004
  • mitre_attack — T1547.001
  • mitre_attack — T1041
  • mitre_attack — T1071

Entities

Dark Caracal (threat_actor)Arctic Wolf (vendor)Ethereum (technology)