Dark Caracal Hackers Use Ethereum Blockchain to Keep New Malware Connected After C2 Disruption
Brief
Dark Caracal has returned with a new tool that helps attackers stay connected when defenders shut down their control servers.
The cyberespionage group is linked by researchers to a Venezuelan communications organization intrusion, where it deployed an unfamiliar Go-based malware framework called GoCaracal alongside its long-used Bandook backdoor.
The campaign begins with Spanish-language financial and tax lures sent through phishing emails.
Weaponized SVG image files conceal shortened links and redirect recipients to payload hosting sites, a technique seen across other malicious SVG delivery campaigns .
The operators then provide an archive that starts a small implant and opens the door to more capable tools. Analysts at Arctic Wolf identified GoCaracal while investigating the June 2026 breach, and assessed that Dark Caracal was responsible.
