GoCaracal is a previously undocumented Go-based malware framework used in a June 2026 intrusion. It provides remote shell access, payload execution, and in its extended profile adds browser data theft, keylogging, remote desktop control, and SOCKS5 proxying. It uses an Ethereum smart contract to fetch replacement C2 addresses.