← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 28, 2026 · 07:54via Cyber Security News

Dark Caracal Hackers Use Ethereum Blockchain to Keep New Malware Connected After C2 Disruption

Brief

Dark Caracal has returned with a new tool that helps attackers stay connected when defenders shut down their control servers.

The cyberespionage group is linked by researchers to a Venezuelan communications organization intrusion, where it deployed an unfamiliar Go-based malware framework called GoCaracal alongside its long-used Bandook backdoor.

The campaign begins with Spanish-language financial and tax lures sent through phishing emails.

Weaponized SVG image files conceal shortened links and redirect recipients to payload hosting sites, a technique seen across other malicious SVG delivery campaigns .

The operators then provide an archive that starts a small implant and opens the door to more capable tools. Analysts at Arctic Wolf identified GoCaracal while investigating the June 2026 breach, and assessed that Dark Caracal was responsible.

Read more on Cyber Security News