Post
MEDIUM

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

· malware

Arctic Wolf linked a previously undocumented Go-based malware framework, dubbed GoCaracal, to Dark Caracal with medium confidence, following a June 2026 intrusion at a communications organization in Venezuela.

GoCaracal provides remote shell access and payload execution, and an extended profile adds browser data theft, keylogging, and remote desktop control. Notably, the malware fetches replacement C2 infrastructure via an Ethereum smart contract, complicating takedown efforts.