Dark Caracal is a threat actor with a documented history of operating in Latin America. Arctic Wolf linked the GoCaracal malware campaign to Dark Caracal with medium confidence based on Bandook use, Delphi-loader characteristics, Spanish-language lures, and regional targeting.