Dark Caracal Expands Espionage Arsenal with GoCaracal Framework and AsioGate Backdoor — Threadlinqs Intelligence
As of 2026-08-26, Dark Caracal Expands Espionage Arsenal with GoCaracal Framework and AsioGate Backdoor is a high-severity apt threat attributed to Dark Caracal (Lebanon), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 28 indicators of compromise.
Threat ID: TL-2026-2158 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: Dark Caracal · Lebanon · ESPIONAGE
Dark Caracal, a Lebanese mercenary espionage group with medium-confidence links to the General Directorate of General Security (GDGS), has fielded GoCaracal, a previously undocumented modular Go-based
Arctic Wolf Labs disclosed a refreshed Dark Caracal malware arsenal deployed against a Venezuelan communications organization in June 2026, with moderate-confidence spillover into Brazil, Ecuador, Chile, Colombia, El Salvador, and Uruguay. The intrusion began with Spanish-language, tax/financial-themed phishing emails carrying a weaponized SVG attachment. The SVG embeds a Base64-encoded shortened URL that redirects the victim's browser through an intermediate redirector to getpdfdigital[.]cloud, an attacker-controlled staging site, which serves a 7-Zip archive containing a lightweight GoCaracal implant (tf-oficina004a9.exe). That implant deploys a Delphi loader, which in turn delivers an extended GoCaracal build plus a payload of the Bandook remote-access trojan.
GoCaracal is a previously undocumented modular framework written in Go. Arctic Wolf reconstructed its development across four phases from January to July 2026: a January foundation phase building core communications and host-profiling code; a February-April phase reorganizing the codebase into reusable modules and adding antivirus/security-software discovery and interactive shell functionality; a May-June phase expanding the extended build with self-update capability; and a June-July phase operationalizing a blockchain-based C2 fallback and registering new delivery domains. GoCaracal's lightweight build uses a custom packet protocol with AES-GCM encryption and numeric packet identifiers; its extended build adds code/shellcode injection, an interactive command shell for the operator, and the ability to query the Ethereum blockchain for C2 configuration via public eth_getStorageAt JSON-RPC calls.
The most novel element is BulletproofC2: a custom Solidity smart contract (0x03D605f13A74Bfb6149078122FcF62BD6d8799d8) deployed to Ethereum mainnet on 2026-05-20 after prior trials on the Sepolia testnet, which stores a single owner-mutable value (observed holding both public IPs and RFC 1918 addresses) that infected hosts poll to learn current C2 infrastructure. Three additional, apparently identical contracts were deployed from the same management wallet (0x7D321FE277f8c25aaC14aF1BA3Fc34953242052F), giving the operators a resilient, censorship-resistant fallback channel that is difficult to take down via conventional domain/IP blocking.
Alongside GoCaracal, Dark Caracal deployed an updated Bandook variant with randomized command identifiers (replacing the historical sequential @0001-@0136 numbering) and obfuscated, generically named plugin exports, with a reduced set of roughly 82 command handlers versus older builds. Persistence on both malware families relies on Windows Registry Run-key manipulation, including a concealed NTUSER.MAN artifact tied to the Run-key workflow. GoCaracal infrastructure preferentially uses AEZA Group hosting, while Bandook C2 infrastructure is hosted primarily via AlexHost.
Arctic Wolf attributes the campaign to Dark Caracal (MITRE ATT&CK G0070) with medium confidence, based on the continued use of Bandook, recurring Delphi-loader characteristics, Spanish-language tax-themed phishing lures, malicious-SVG delivery, URL-shortener abuse, document-themed staging infrastructure, and consistent LATAM targeting matching the group's established pattern. Dark Caracal has been linked with medium confidence to Lebanon's General Directorate of General Security (GDGS) since at least 2012, and has historically targeted governments, businesses, journalists, and activists using malware including Bandook, CrossRAT, FinFisher, and the Android RAT Pallas. The group's most recent prior documented LATAM operation used Poco RAT against banking, manufacturing, healthcare, pharmaceutical, and logistics enterprises in Venezuela, Chile, the Dominican Republic, Colombia, and Ecuador via similar Spanish-language invoice-themed phishing. Arctic Wolf assesses GoCaracal is augmenting, not yet replacing, Bandook, with functional overlap in remote access, execution, payload de
Target sectors: telecoms, government administration, financial-services, health, manufacturing, pharmaceuticals, logistics, news - media, civil society
Target regions: Latin America, venezuela, brazil, ecuador, chile, colombia, el salvador, uruguay
Timeline
- Arctic Wolf reconstructs GoCaracal's earliest development phase: core communications and host-profiling modules laid down.
- Kaspersky publicly reports a Dark Caracal campaign delivering the previously unseen C++ AsioGate backdoor via SVG-based phishing techniques targeting Venezuelan entities.
- GoCaracal reorganized into reusable modules; antivirus/security-software discovery and interactive shell functionality added (phase runs through approximately April 2026).
- The BulletproofC2 Solidity smart contract (0x03D605f13A74Bfb6149078122FcF62BD6d8799d8) is deployed to Ethereum mainnet after prior Sepolia testnet trials.
- GoCaracal's extended build gains self-update capability and blockchain-based C2 fallback logic.
- Arctic Wolf Labs investigates a confirmed intrusion at a Venezuelan communications organization involving GoCaracal, the updated Bandook variant, and BulletproofC2.
- A new domain used to deliver GoCaracal is registered; Arctic Wolf observes continued operator testing.
- Arctic Wolf Labs publishes "Dark Caracal Reloaded: New Malware, Same Hunting Grounds"; Dark Reading covers the findings.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 28 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1583, T1566, T1204, T1059, T1547, T1140, T1027, T1055, T1518, T1057