Arctic Wolf has disclosed details of a previously undocumented Go based malware framework known as GoCaracal, which researchers have linked with medium confidence to the threat group Dark Caracal. The malware was identified during a June 2026 intrusion targeting an unnamed communications organization in Venezuela. According to the security firm, GoCaracal provides attackers with remote shell access and the ability to execute malicious payloads while also supporting a broader range of post compromise activities through an extended feature set. Arctic Wolf assessed the connection to Dark Caracal based on similarities in malware delivery methods, infrastructure, Spanish language financial themed lures, malicious SVG files, URL shortening services, hosting provider preferences, and historical targeting across Latin America. To support detection efforts, the company also released a YARA rule and representative indicators of compromise that security teams can use to identify potential infections.
The malware operates through two separate profiles that provide different levels of functionality depending on the attackers’ objectives. The lightweight version focuses on host profiling, encrypted command and control communications, interactive shell access, payload retrieval and execution, and shellcode loading and injection. The extended profile significantly expands these capabilities by enabling system and file discovery, browser cookie and credential theft, keylogging, command execution, targeted file searches, WebRTC based remote desktop access, hidden browser interaction, SOCKS5 proxy functionality, and persistence related operations. Arctic Wolf also observed Bandook malware being deployed alongside the lightweight GoCaracal profile during the investigated intrusion. However, researchers stated that current evidence does not indicate that GoCaracal has replaced Bandook, suggesting that both malware families may be used together depending on operational requirements.
One of the most notable technical features identified in GoCaracal is its use of an Ethereum smart contract as a fallback mechanism for maintaining command and control communications. The malware first attempts to connect to its configured command and control server using conventional methods. If repeated connection attempts fail, it sends an eth_getStorageAt request to a public Ethereum JSON RPC endpoint to retrieve a replacement command and control address stored within a smart contract. The newly obtained address is written into the malware’s memory before it attempts to reconnect using the updated infrastructure. According to Arctic Wolf, this approach does not move the malware’s full command and control operations onto the Ethereum blockchain. Instead, it provides operators with a flexible method of updating fallback infrastructure without distributing a new malware version. Researchers noted that multiple public Ethereum RPC endpoints can retrieve the same contract data, reducing reliance on a single service. The report did not confirm whether this fallback mechanism was successfully used during the investigated intrusion.
Arctic Wolf believes phishing was the most likely infection vector, although investigators were unable to recover the original phishing email or malicious SVG attachment from the affected organization. This assessment was based on financial and tax themed file names, more than 100 related malicious SVG samples communicating with the same hosting infrastructure, and campaign characteristics previously associated with Dark Caracal. The report also identified related infrastructure and artifacts connected to Brazil, Ecuador, Chile, Colombia, El Salvador, and Uruguay, although these countries were not confirmed as victims of the campaign. Alongside its technical analysis, Arctic Wolf released representative indicators of compromise, including YARA detection rules, SHA 256 file hashes, associated domains and IP addresses, Ethereum contract and wallet indicators, and malware related host paths. Researchers noted that the publicly available indicators represent only part of the full dataset, with additional threat intelligence available to Arctic Wolf customers.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





