← Threat Actors & APT Groups

Dark Caracal

Every article that identifies Dark Caracal as responsible for or connected to reported activity.

MalwareThe Hacker News·10 hours ago

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

Threat actors associated with Dark Caracal deployed GoCaracal, a previously undocumented Go-based malware framework, during a June 2026 intrusion against a communications organization in Venezuela. GoCaracal leverages an Ethereum smart contract to dynamically retrieve replacement command-and-control addresses, enabling operators to maintain persistence while evading detection. The malware provides remote shell access, payload execution, browser data theft, keylogging, and remote desktop control capabilities.