INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Dark Caracal Deploys Go Malware with Ethereum C2 fallback
| 2026-08-27 09:33 CRITICAL LOW MALWARE & BOTNETS
Executive Summary
AI-generated
The threat landscape is evolving with the deployment of new Dark Caracal malware, specifically GoCaracal, which boasts an Ethereum-based C2 fallback. This sophisticated toolkit has been linked to Lebanon's General Directorate of General Security (GDGS), a notorious cyberespionage group associated with targeted intrusions against governments and organizations worldwide. The malware is designed for resilient communication, incorporating features such as file management, browser credential theft, cookie theft, keylogging, and remote desktop capabilities. Its focus remains on Latin America, where Dark Caracal has established a foothold in recent campaigns targeting Singapore, Cyprus, Chile, Italy, the USA, Turkey, Switzerland, Indonesia, and Germany.
Technical Mitigations AI-generated
* Use of a shared architecture for both lightweight and extended build profiles, allowing attackers to easily switch between the two without requiring significant modifications.
* The use of Ethereum smart-contract fallbacks, which can be used to retrieve replacement command-and-control (C2) infrastructure even if the malware cannot reach its primary C2 after repeated tries.
* Phishing emails with financial or tax lures that drop weaponized SVG attachments, redirecting victims through URL shorteners to attacker-controlled sites that serve malicious payloads.
* The use of a Delphi loader carrying Bandook and an extended GoCaracal build with broader post-compromise features, allowing attackers to maintain persistence mechanisms even after the initial payload is executed.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Dark CaracalDark CaracalTransparent TribeTransparent Tribe
BandookBandookGrandoreiroGrandoreiro
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
LATAM
LATAM
ASEAN
ASEAN
DACH
DACH
cryptocurrencycryptocurrency
Incident Timeline
June 2026
Threat actors linked by Arctic Wolf to Dark Caracal deployed a previously undocumented Go-based malware framework, GoCaracal.
Click on any entity below to view its context and source!
target_region
Venezuela, Bolivarian Republic of
Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework,
GoCaracal
, during a June 2026 intrusion at an unnamed communications organization in Venezuela.
Arctic Wolf Labs researchers link a June 2026 intrusion against a communications organisation in Venezuela to the Lebanon‑linked espionage group, and says it deployed a previously undocumented Go‑based framework called GoCaracal alongside an updated Bandook backdoor.
“In June 2026, Arctic Wolf Labs investigated a targeted intrusion affecting a communications organization in Venezuela.
Related:
'Grandoreiro' Malware Resurfaces With Mexico Campaign
In the June 2026 intrusion that Arctic Wolf investigated at a Venezuelan communications organization, researchers found GoCaracal deployed alongside an updated version of Bandook.
threat_actor
Dark Caracal
Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework,
GoCaracal
, during a June 2026 intrusion at an unnamed communications organization in Venezuela.
The Hacker News covered
the original Dark Caracal disclosure
in 2018, followed by
retooled Bandook malware
in 2020 and
Bandook attacks in Venezuela
in 2021.
Dark Caracal has a documented history of operating in Latin America.
"We assess with medium confidence that this activity is linked to Dark Caracal," Arctic Wolf said.
malware
Bandook
Arctic Wolf Labs researchers link a June 2026 intrusion against a communications organisation in Venezuela to the Lebanon‑linked espionage group, and says it deployed a previously undocumented Go‑based framework called GoCaracal alongside an updated Bandook backdoor.
The June 2026 Bandook sample shows deliberate anti‑analysis tweaks.
Related:
'Grandoreiro' Malware Resurfaces With Mexico Campaign
In the June 2026 intrusion that Arctic Wolf investigated at a Venezuelan communications organization, researchers found GoCaracal deployed alongside an updated version of Bandook.
tactic
Espionage
Arctic Wolf Labs researchers link a June 2026 intrusion against a communications organisation in Venezuela to the Lebanon‑linked espionage group, and says it deployed a previously undocumented Go‑based framework called GoCaracal alongside an updated Bandook backdoor.
organisation
SVG
Related:
Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks
"The infrastructure associated with the June 2026 intrusion forms part of a broader cluster of Spanish-language, document-themed domains used to deliver malicious SVG files and downstream payloads," Arctic Wolf researchers wrote in the report.
Arctic Wolf assesses phishing as the delivery mechanism, although it did not recover the original phishing email or Scalable Vector Graphics (SVG) attachment from the victim.
source_region
Pakistan
Related:
Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks
"The infrastructure associated with the June 2026 intrusion forms part of a broader cluster of Spanish-language, document-themed domains used to deliver malicious SVG files and downstream payloads," Arctic Wolf researchers wrote in the report.
threat_actor
Transparent Tribe
Related:
Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks
"The infrastructure associated with the June 2026 intrusion forms part of a broader cluster of Spanish-language, document-themed domains used to deliver malicious SVG files and downstream payloads," Arctic Wolf researchers wrote in the report.
source_region
Afghanistan
Related:
Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks
"The infrastructure associated with the June 2026 intrusion forms part of a broader cluster of Spanish-language, document-themed domains used to deliver malicious SVG files and downstream payloads," Arctic Wolf researchers wrote in the report.
tactic
T1588.001 - Malware
Related:
'Grandoreiro' Malware Resurfaces With Mexico Campaign
In the June 2026 intrusion that Arctic Wolf investigated at a Venezuelan communications organization, researchers found GoCaracal deployed alongside an updated version of Bandook.
target_region
Mexico
Related:
'Grandoreiro' Malware Resurfaces With Mexico Campaign
In the June 2026 intrusion that Arctic Wolf investigated at a Venezuelan communications organization, researchers found GoCaracal deployed alongside an updated version of Bandook.
malware
Grandoreiro
Related:
'Grandoreiro' Malware Resurfaces With Mexico Campaign
In the June 2026 intrusion that Arctic Wolf investigated at a Venezuelan communications organization, researchers found GoCaracal deployed alongside an updated version of Bandook.
organisation
The Hacker News
The Hacker News covered
the original Dark Caracal disclosure
in 2018, followed by
retooled Bandook malware
in 2020 and
Bandook attacks in Venezuela
in 2021.
organisation
Delphi-loader
Arctic Wolf based the assessment on Bandook use, recurring Delphi-loader characteristics, Spanish-language financial lures, malicious SVGs, URL shorteners, document-themed infrastructure, hosting-provider preferences, and Latin American targeting.
organisation
GoCaracal
GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds browser data theft, keylogging, remote desktop control, and SOCKS5 proxying.
organisation
Scalable Vector Graphics
Arctic Wolf assesses phishing as the delivery mechanism, although it did not recover the original phishing email or Scalable Vector Graphics (SVG) attachment from the victim.
organisation
YARA
Arctic Wolf also published a YARA rule and representative indicators of compromise (IoCs) that defenders can use to hunt for the malware.
organisation
Ethereum
"This mechanism does not place the malware’s full command-and-control channel on Ethereum," Arctic Wolf said.
organisation
IP
Representative SHA-256 hashes and related domains and IP addresses.
data_breach
100 related SVG files
The firm based that assessment on financial and tax-themed artifact naming, the established campaign pattern, and more than 100 related SVG files that communicated with the same malicious hosting site.
July 2026
Arctic Wolf researchers identified seven related Spanish-language document-themed domains used to deliver malicious SVGs and downstream payloads.
January to July 2026
Arctic Wolf detected 249 related samples of GoCaracal malware that used an Ethereum smart contract to automatically update the C2 (command and control) address.
Click on any entity below to view its context and source!
general_metric
249 related samples
Arctic Wolf traced 249 related samples from January to July 2026 and sees a clear development arc.
2026/08/27
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address.
Click on any entity below to view its context and source!
threat_actor
Dark Caracal
Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback
Dark Caracal targets Venezuela with GoCaracal, an upgraded Bandook toolkit and an Ethereum fallback for resilient C2 communications.
We assess with medium confidence that this activity is linked to Dark Caracal, a cyberespionage group associated with Lebanon’s General Directorate of General Security (GDGS) that has historically targeted governments, businesses, journalists, and activists.”
Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback.
Dark Caracal
is back with new malware and the same hunting grounds.
Dark Caracal is an APT group associated with the Lebanese General Directorate of General.
The wider campaign still looks like Dark Caracal.
Of 24 unique C2 addresses extracted from GoCaracal samples, 23 sat on AEZA Group‑operated networks, while Bandook C2 addresses were hosted on AlexHost, a provider previously associated with Dark Caracal.
“Taken together, the findings show Dark Caracal is preserving familiar targeting and delivery practices while modernizing their malware and infrastructure.” concludes the report.
“Dark Caracal’s continued use of established tooling such as Bandook, combined with the introduction of GoCaracal and its separate C2 footprint, suggests an expanding and increasingly compartmentalized toolkit rather than a wholesale change in operational strategy.”
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, malware)
The Lebanon-linked Dark Caracal threat group has upgraded its cyberespionage arsenal with a previously unknown malware framework that gives the threat actor broader capabilities for stealing data and maintaining persistent access to compromised systems.
Dark Caracal is a long-running cyber-espionage operation that researchers have previously linked to Lebanon's General Directorate of General Security (GDGS).
The security company said its telemetry points to potential targeting in Brazil, Ecuador, Uruguay, El Salvador, Colombia and Chile, although the evidence linking all of the activity to Dark Caracal is not equally strong.
Related:
China-Linked Hacker Shows AI Capabilities in APAC Attack
For organizations in the crosshairs of cyber-espionage groups like Dark Caracal, the bigger risk often has to do with the attackers establishing and maintaining a persistent, undetected foothold in the target environment.
Dark Caracal Adds New Malware to Cyber Espionage Arsenal.
Dark Caracal's malware toolkit includes Pallas a custom-developed toolkit for stealing data from Android devices and a custom version of Bandook, a commercially available Windows
remote access Trojan
that multiple threat actors have been using since 2007.
Dark Caracal's New Tricks
In a report this week
According to Arctic Wolf, Dark Caracal appears to be maintaining its established targeting and delivery tactics in its ongoing Latin American campaign, using Spanish-language, financial, and document-themed lures to deliver malicious SVG files and subsequent payloads.
Arctic Wolf interpreted that as a sign that Dark Caracal actors are using GoCaracal to complement Bandook's capabilities rather than to replace it outright, at least for the moment.
The threat actors, however, appear to have replaced their earlier AsioGate malware for initial access and post-compromise activities with Dark Caracal, which they are using for file collection, credential theft, keystroke logging, remote shell access and other intelligence-gathering activities.
Arctic Wolf has provided indicators of compromise and other information that organizations can use to search for or detect signs of malicious activity tied to Dark Caracal activity.
organisation
GoCaracal
Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback
Dark Caracal targets Venezuela with GoCaracal, an upgraded Bandook toolkit and an Ethereum fallback for resilient C2 communications.
Researchers at Arctic Wolf
discovered the new malware
when investigating a targeted intrusion in Venezuela and are tracking the new framework as GoCaracal.
organisation
Ethereum
Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback
Dark Caracal targets Venezuela with GoCaracal, an upgraded Bandook toolkit and an Ethereum fallback for resilient C2 communications.
The malware's support for an Ethereum-based C2 fallback is indication of its growing sophistication and resilience against takedown attempts.
organisation
General Directorate of General Security
We assess with medium confidence that this activity is linked to Dark Caracal, a cyberespionage group associated with Lebanon’s General Directorate of General Security (GDGS) that has historically targeted governments, businesses, journalists, and activists.”
Dark Caracal is a long-running cyber-espionage operation that researchers have previously linked to Lebanon's General Directorate of General Security (GDGS).
organisation
APT
Dark Caracal is an APT group associated with the Lebanese General Directorate of General.
organisation
the Lebanese General Directorate of General
Dark Caracal is an APT group associated with the Lebanese General Directorate of General.
organisation
AEZA
Of 24 unique C2 addresses extracted from GoCaracal samples, 23 sat on AEZA Group‑operated networks, while Bandook C2 addresses were hosted on AlexHost, a provider previously associated with Dark Caracal.
organisation
SecurityAffairs
“Dark Caracal’s continued use of established tooling such as Bandook, combined with the introduction of GoCaracal and its separate C2 footprint, suggests an expanding and increasingly compartmentalized toolkit rather than a wholesale change in operational strategy.”
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, malware)
organisation
Cyber Espionage Arsenal
Dark Caracal Adds New Malware to Cyber Espionage Arsenal.
infrastructure
Android
Dark Caracal's malware toolkit includes Pallas a custom-developed toolkit for stealing data from Android devices and a custom version of Bandook, a commercially available Windows
remote access Trojan
that multiple threat actors have been using since 2007.
infrastructure
Windows
Dark Caracal's malware toolkit includes Pallas a custom-developed toolkit for stealing data from Android devices and a custom version of Bandook, a commercially available Windows
remote access Trojan
that multiple threat actors have been using since 2007.
organisation
Delphi
It establishes a foothold and then pulls in a Delphi loader carrying Bandook and a more capable, extended GoCaracal build with broader post‑compromise features.
organisation
SVG
Phishing emails with financial or tax lures drop weaponised SVG attachments, which redirect victims through URL shorteners to attacker‑controlled sites that serve the real payload.
data_breach
100 related SVG files
“While Arctic Wolf did not recover the original phishing email or SVG attachment associated with the intrusion, the artifact’s financial and tax-themed filename, the campaign’s established delivery pattern, and more than 100 related SVG files found communicating with the same malicious hosting site support our assessment that the file was delivered through phishing.” continues the report.
organisation
Fetch Replacement C2 Address
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address.
organisation
IP
Transaction records show that the attackers changed the address to a public IP, suggesting they tested and used the system.
organisation
HOST
The extended GoCaracal configuration can include an Ethereum smart‑contract address alongside the usual HOST and PORT values.
organisation
Solidity
Arctic Wolf found a custom Solidity contract called BulletproofC2 that stores a changeable C2 address.
organisation
Ethereum’s Sepolia
The same wallet also deployed similar contracts on Ethereum’s Sepolia testnet before moving some to the mainnet.
organisation
@0001
Sequential command identifiers like @0001 through @0136 were replaced with randomised strings, and plugin export names were obfuscated with generic labels, preserving functionality while weakening signature‑based detection built on older naming conventions.
organisation
GoCaracal Under Active Development
GoCaracal
GoCaracal Under Active Development
GoCaracal is malware the threat actor has been actively developing throughout 2026, Arctic Wolf said.
Tactical Metrics
Metrics
data_breach
100
Related Svg Files
Click for context!
The firm based that assessment on financial and tax-themed artifact naming, the established campaign pattern, and more than 100 related SVG files that communicated with the same malicious hosting site.
…the intrusion, the artifact’s financial and tax-themed filename, the campaign’s established delivery pattern, and more than 100 related SVG files found communicating with the same malicious hosting site support our assessment that the file was deli…
Metrics
infrastructure
Android
Affected Product
Dark Caracal's malware toolkit includes Pallas a custom-developed toolkit for stealing data from Android devices and a custom version of Bandook, a commercially available Windows
remote access Trojan
that multiple threat actors have been using si…
Metrics
infrastructure
Windows
Affected Product
…cal's malware toolkit includes Pallas a custom-developed toolkit for stealing data from Android devices and a custom version of Bandook, a commercially available Windows
remote access Trojan
that multiple threat actors have been using since 2007.
Intelligence Sources
Dark Reading
2026-08-26
The Hacker News
2026-08-27
Security Affairs
2026-08-27
Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback
Security Affairs
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-28T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
21x
organisation
Identified Entity
The Hacker News
entity
15x
target region
Target Country
Venezuela, Bolivarian Republic of
country
10x
source region
Origin Country
Brazil
country
8x
timeline
Temporal Reference
June 2026
date
3x
tactic
Cyber Operation Type
Keylogging
tactic
2x
threat actor
APT Group
Dark Caracal
actor
2x
malware
Malware Payload
Bandook
tool
2x
tactic
MITRE ATT&CK Technique
T1588.001 - Malware
technique
2x
general metric
Samples
23
samples
2x
infrastructure
Affected Product
Android
software
Contextual Telemetry
Context Block
7 METRICS
target region
Target Region
LATAM
region
data breach
Related Svg Files
100
related svg files
general metric
Related Samples
249
related samples
general metric
Unique C2 Addresses
24
unique c2 addresses
source region
Origin Region
APAC
region
industry
Targeted Sector
Government
sector
attribution
Attributing Entity
AsioGate
authority
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.