Malware Linked to Dark Caracal Uses Ethereum as a Backup When Servers Get Taken Down
Want more insights like this?
Arctic Wolf has uncovered a new Go-based malware framework, GoCaracal, deployed alongside the long-running Bandook backdoor against a communications organization in Venezuela in June 2026. Researchers assess with medium confidence that the activity is linked to Dark Caracal, a cyberespionage group with a long history in Latin America.
Attacks begin with Spanish-language emails on financial and tax themes, carrying weaponized SVG attachments. The SVG holds no payload — just an encoded shortened link that redirects through intermediaries to a 7-Zip archive containing the first-stage implant, which is why the attachment slips past filters.
GoCaracal ships in two builds. The lightweight one establishes access and delivers payloads; the extended one handles control and intelligence collection, and it is the one with the blockchain trick. When it loses contact with its primary server, it queries an Ethereum smart contract named BulletproofC2 for a replacement address — no new file needed on the victim's device.
Arctic Wolf also assesses with moderate confidence that related activity reaches Brazil, Ecuador, Chile, Colombia, El Salvador, and Uruguay, though the regional scope is still under investigation. Treat SVG attachments as active content, watch for failed control-server connections followed by Ethereum RPC requests, and read a single takedown as one step, not the end of the intrusion.
Source: Cyber Security News