INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Dark Caracal Deploys Go Malware with Ethereum C2 fallback

| 2026-08-27 09:33 CRITICAL LOW MALWARE & BOTNETS
Executive Summary
AI-generated
The threat landscape is evolving with the deployment of new Dark Caracal malware, specifically GoCaracal, which boasts an Ethereum-based C2 fallback. This sophisticated toolkit has been linked to Lebanon's General Directorate of General Security (GDGS), a notorious cyberespionage group associated with targeted intrusions against governments and organizations worldwide. The malware is designed for resilient communication, incorporating features such as file management, browser credential theft, cookie theft, keylogging, and remote desktop capabilities. Its focus remains on Latin America, where Dark Caracal has established a foothold in recent campaigns targeting Singapore, Cyprus, Chile, Italy, the USA, Turkey, Switzerland, Indonesia, and Germany.
Technical Mitigations AI-generated
* Use of a shared architecture for both lightweight and extended build profiles, allowing attackers to easily switch between the two without requiring significant modifications. * The use of Ethereum smart-contract fallbacks, which can be used to retrieve replacement command-and-control (C2) infrastructure even if the malware cannot reach its primary C2 after repeated tries. * Phishing emails with financial or tax lures that drop weaponized SVG attachments, redirecting victims through URL shorteners to attacker-controlled sites that serve malicious payloads. * The use of a Delphi loader carrying Bandook and an extended GoCaracal build with broader post-compromise features, allowing attackers to maintain persistence mechanisms even after the initial payload is executed.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Dark CaracalDark CaracalTransparent TribeTransparent Tribe BandookBandookGrandoreiroGrandoreiro
Target & Sectors
NORTH_AMERICA NORTH_AMERICA LATAM LATAM ASEAN ASEAN DACH DACH cryptocurrencycryptocurrency
Incident Timeline
‎June 2026
Threat actors linked by Arctic Wolf to Dark Caracal deployed a previously undocumented Go-based malware framework, GoCaracal.
target_region Venezuela, Bolivarian Republic of
threat_actor Dark Caracal
malware Bandook
tactic Espionage
organisation SVG
source_region Pakistan
threat_actor Transparent Tribe
source_region Afghanistan
tactic T1588.001 - Malware
target_region Mexico
malware Grandoreiro
organisation The Hacker News
organisation Delphi-loader
organisation GoCaracal
organisation Scalable Vector Graphics
organisation YARA
organisation Ethereum
organisation IP
data_breach 100 related SVG files
‎July 2026
Arctic Wolf researchers identified seven related Spanish-language document-themed domains used to deliver malicious SVGs and downstream payloads.
‎January to July 2026
Arctic Wolf detected 249 related samples of GoCaracal malware that used an Ethereum smart contract to automatically update the C2 (command and control) address.
general_metric 249 related samples
‎2026/08/27
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address.
threat_actor Dark Caracal
organisation GoCaracal
organisation Ethereum
organisation General Directorate of General Security
organisation APT
organisation the Lebanese General Directorate of General
organisation AEZA
organisation SecurityAffairs
organisation Cyber Espionage Arsenal
infrastructure Android
infrastructure Windows
organisation Delphi
organisation SVG
data_breach 100 related SVG files
organisation Fetch Replacement C2 Address
organisation IP
organisation HOST
organisation Solidity
organisation Ethereum’s Sepolia
organisation @0001
organisation GoCaracal Under Active Development GoCaracal
Tactical Metrics
Metrics
data_breach
100
Related Svg Files
Metrics
infrastructure
‎Android
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Intelligence Sources