Blocking a malware control server is usually not enough if the new address can be picked up directly from the blockchain. The specialists of Arctic Wolf discovered at the group Dark Caracal previously unknown modular malware GoCaracal, which is able to restore communication with operators through the smart contract Ethereum.
GoCaracal was found during an investigation into a targeted campaign against a telecommunications organization in Venezuela in June 2026. Arctic Wolf with medium confidence links the operation with Dark Caracal, which was previously associated with the General Directorate of General Security of Lebanon. The group has been interested in state structures, companies, journalists and activists for many years.
The chain of infection has preserved the familiar for Dark Caracal scheme. The victims were sent Spanish-language baits on financial and tax topics with malicious SVG files. Inside was a coded shortened link, which through several redirects led to the site controlled by the attackers. The site was archived with a lightweight version of GoCaracal.
Analysis of 249 samples showed that the developers support two variants of GoCaracal. The compact version collects computer information, establishes an encrypted connection to the control server, runs commands, downloads files, and implements code into other processes. This option is needed primarily in order to secure itself in the system and deliver additional components.
The extended build is designed for long-term espionage and contains 34 team handlers. GoCaracal is able to search and download files, collect browser data, record keystrokes, run hidden browser sessions, provide remote desktop access via WebRTC, and turn an infected computer into a SOCKS5 proxy. The development took place at least from January to July 2026, and the set of possibilities gradually grew from a simple implant to a full-fledged remote control.
An unusual mechanism appeared in extended assemblies in the summer. After several failed attempts to contact the main GoCaracal control server, you can contact the public node of Ethereum and read the value from a predetermined smart contract. The found BulletproofC2 contract stores the address of the backup server, which the operator is able to change the new transaction.
The control traffic through Ethereum does not pass. Blockchain serves as a sustainable guide with an up-to-date infrastructure address. After changing the server, already infected computers do not need a new version of GoCaracal, and blocking one domain or IP address does not deprive operators of the ability to return communication. Arctic Wolf also discovered several similar contracts, which were first checked in the Sepolia test network and then deployed to the main Ethereum network.
In the same operation, Dark Caracal continued to use the long-known Trojan of remote access Bandook. The fresh version received random command identifiers instead of the previous serial numbering and hidden names of the components, which complicates the search for old signatures. The malware also knows how to extract credentials from Chrome, Brave and Firefox.
Arctic Wolf does not yet consider GoCaracal a replacement for Bandook. Both programs worked in parallel, but the possibilities of the new framework largely intersect with the functions of the old Trojan. Associated artifacts and infrastructure specialists also нашлиfound in Brazil, Ecuador, Chile, Colombia, El Salvador and Uruguay, so Dark Caracal's activity probably covers a significant part of Latin America.
GoCaracal was found during an investigation into a targeted campaign against a telecommunications organization in Venezuela in June 2026. Arctic Wolf with medium confidence links the operation with Dark Caracal, which was previously associated with the General Directorate of General Security of Lebanon. The group has been interested in state structures, companies, journalists and activists for many years.
The chain of infection has preserved the familiar for Dark Caracal scheme. The victims were sent Spanish-language baits on financial and tax topics with malicious SVG files. Inside was a coded shortened link, which through several redirects led to the site controlled by the attackers. The site was archived with a lightweight version of GoCaracal.
Analysis of 249 samples showed that the developers support two variants of GoCaracal. The compact version collects computer information, establishes an encrypted connection to the control server, runs commands, downloads files, and implements code into other processes. This option is needed primarily in order to secure itself in the system and deliver additional components.
The extended build is designed for long-term espionage and contains 34 team handlers. GoCaracal is able to search and download files, collect browser data, record keystrokes, run hidden browser sessions, provide remote desktop access via WebRTC, and turn an infected computer into a SOCKS5 proxy. The development took place at least from January to July 2026, and the set of possibilities gradually grew from a simple implant to a full-fledged remote control.
An unusual mechanism appeared in extended assemblies in the summer. After several failed attempts to contact the main GoCaracal control server, you can contact the public node of Ethereum and read the value from a predetermined smart contract. The found BulletproofC2 contract stores the address of the backup server, which the operator is able to change the new transaction.
The control traffic through Ethereum does not pass. Blockchain serves as a sustainable guide with an up-to-date infrastructure address. After changing the server, already infected computers do not need a new version of GoCaracal, and blocking one domain or IP address does not deprive operators of the ability to return communication. Arctic Wolf also discovered several similar contracts, which were first checked in the Sepolia test network and then deployed to the main Ethereum network.
In the same operation, Dark Caracal continued to use the long-known Trojan of remote access Bandook. The fresh version received random command identifiers instead of the previous serial numbering and hidden names of the components, which complicates the search for old signatures. The malware also knows how to extract credentials from Chrome, Brave and Firefox.
Arctic Wolf does not yet consider GoCaracal a replacement for Bandook. Both programs worked in parallel, but the possibilities of the new framework largely intersect with the functions of the old Trojan. Associated artifacts and infrastructure specialists also нашлиfound in Brazil, Ecuador, Chile, Colombia, El Salvador and Uruguay, so Dark Caracal's activity probably covers a significant part of Latin America.