CyberSecurityBoardThreat Intel · CVEs · Products
Malware

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

August 27, 2026

Arctic Wolf has disclosed a previously undocumented Go-based malware framework, GoCaracal, used in a June 2026 intrusion at an unnamed communications organization in Venezuela. The threat actors, linked by Arctic Wolf to Dark Caracal with medium confidence, deployed GoCaracal alongside Bandook malware. GoCaracal provides remote shell access and payload execution, with an extended profile adding browser data theft, keylogging, remote desktop control, and SOCKS5 proxying.

Arctic Wolf assesses phishing as the delivery mechanism, based on financial and tax-themed artifact naming and over 100 related SVG files communicating with the same malicious hosting site. The extended GoCaracal profile attempts to communicate with its primary C2 server; after repeated failures, it sends an eth_getStorageAt request to a public Ethereum JSON-RPC endpoint to retrieve a replacement C2 address stored in a smart contract. This mechanism allows operators to change the C2 address without shipping a new binary, though Arctic Wolf notes it does not place the full C2 channel on Ethereum.

Dark Caracal has a documented history in Latin America, and Arctic Wolf assesses broader regional activity with moderate confidence, though no confirmed victim countries beyond Venezuela are identified. Arctic Wolf published a YARA rule, SHA-256 hashes, domains, IPs, Ethereum contract indicators, and host paths as IoCs. The full set is available to Arctic Wolf customers.

CVEs: CVE-2026-58231

Attack groups: Dark Caracal

Malware: GoCaracal, Bandook

Companies: Arctic Wolf