MalwareThe Hacker News·10 hours ago
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
Threat actors associated with Dark Caracal deployed GoCaracal, a previously undocumented Go-based malware framework, during a June 2026 intrusion against a communications organization in Venezuela. GoCaracal leverages an Ethereum smart contract to dynamically retrieve replacement command-and-control addresses, enabling operators to maintain persistence while evading detection. The malware provides remote shell access, payload execution, browser data theft, keylogging, and remote desktop control capabilities.