GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
Arctic Wolf has disclosed a previously undocumented Go-based malware framework, GoCaracal, used in a June 2026 intrusion at an unnamed communications organization…
Arctic Wolf has disclosed a previously undocumented Go-based malware framework, GoCaracal, used in a June 2026 intrusion at an unnamed communications organization…
GoCaracal is a previously undocumented Go-based malware framework used in a June 2026 intrusion. It provides remote shell access, payload execution, and…
QTBotnet is a platform used by QTFY to command and control compromised devices, capable of launching DDoS attacks and executing commands.
Pinterest is a social media platform that is being abused by PINHOLE RAT as a dead drop resolver to obtain C2 server…
SurveyMonkey is an online survey platform that is being abused by PINHOLE RAT as a dead drop resolver to obtain C2 server…
E4del is a Node.js-based remote access trojan delivered via FTP banner dead drop resolvers. It is embedded in a digitally signed Electron…
QUICAgent is a Golang-based backdoor used in Operation QUICSILVER. It employs sandbox evasion, communicates via QUIC over UDP port 443, and supports…
RedC2 4.0 is the latest version of the RedC2 C2 framework, introducing the RedShell Linux beacon and AI-assisted Red Agent. It is…
RedC2 is a cross-platform command-and-control framework for Windows, macOS, and Linux, marketed on cybercrime forums and sold via Red Offsec. It features…
On August 20, 2026, the Rust Project removed malicious versions of three widely used crates from crates.io after a compromised maintainer account…