← Back
MalwareSecurity Affairs·7 hours ago

Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback

Dark Caracal has deployed GoCaracal, an upgraded variant of the Bandook toolkit, targeting a communications organization in Venezuela with novel command-and-control capabilities. The malware incorporates an Ethereum-based C2 fallback mechanism designed to maintain resilient communications even if primary command channels are disrupted. Arctic Wolf Labs researchers attribute the June 2026 intrusion to the Lebanon-linked espionage group, marking a continuation of their targeting of Venezuelan entities.

Read full article at Security Affairs

Related Articles

MalwareThe Hacker News·18 hours ago

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

Threat actors associated with Dark Caracal deployed GoCaracal, a previously undocumented Go-based malware framework, during a June 2026 intrusion against a communications organization in Venezuela. GoCaracal leverages an Ethereum smart contract to dynamically retrieve replacement command-and-control addresses, enabling operators to maintain persistence while evading detection. The malware provides remote shell access, payload execution, browser data theft, keylogging, and remote desktop control capabilities.

MalwareThe Hacker News·13 hours ago

ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories

A 296K-node IoT botnet and coordinated targeting of over 100 water systems represent escalating threats to critical infrastructure, while researchers have identified a SharePoint RCE exploit chain among emerging vulnerabilities. Social engineering tactics leveraging fake login pages, security scans, and productivity applications continue to serve as effective initial access vectors alongside more sophisticated techniques including AI-augmented botnets and command-and-control traffic obfuscation. The threat landscape this week demonstrates attackers' evolving methods from credential harvesting to supply chain compromise and delayed malware activation to evade detection systems.

MalwareDark Reading·1 day ago

Android Malware Hijacks Update System for Car Head Units

Threat actors operating a click-fraud botnet have discovered a new attack vector by compromising the update mechanisms of Android-based car head units to distribute malware. The attackers are exploiting legitimate system functionality meant for device updates, allowing them to spread infections across vulnerable vehicle infotainment systems.