Threat reportMalwareTL-2026-2219
Dark Caracal Deploys New GoCaracal Malware with Ethereum-Based C2 Resilience in Venezuela Breach
Dark Caracal Deploys New GoCaracal Malware with (TL-2026-2219), also tracked as Dark Caracal Reloaded, is a high-severity malware campaign, first published 2026-08-29. It is attributed to Dark Caracal (Lebanon) with medium confidence, affects Microsoft Windows, maps to 16 MITRE ATT&CK techniques (T1021.005, T1027, T1055), and is covered by 9 detection rules and 30 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 16MITRE ATT&CK
- Actors
- 1Dark Caracal
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 30Indicators of compromise
Key facts for TL-2026-2219
- Threat ID
- TL-2026-2219
- Also known as
- Dark Caracal Reloaded
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- Dark Caracal
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Lebanon
- Motivation
- ESPIONAGE
- Target sectors
- telecoms
- Target regions
- Latin America
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in Dark Caracal Deploys New GoCaracal Malware with
Malware and tooling: Bandook, GoCaracal, 0x03D605f13A74Bfb6149078122FcF62BD6d8799d8, 0x04aB453494381E60171BE04Ea6BE6E7C44EafAfd, 0x7D321FE277f8c25aaC14aF1BA3Fc34953242052F, 0xD7635f31620772882a6712472a6278c53247Bc44, 0xf165F26300BF65DFaC78BC9557326bDbB3C6d33C
How Dark Caracal Deploys New GoCaracal Malware with works
Lebanon-linked cyberespionage group Dark Caracal (G0070) deployed a previously undocumented Go-based malware framework, GoCaracal, alongside its legacy Bandook backdoor in a confirmed June 2026 breach of a Venezuelan communications organization. The extended GoCaracal build queries a custom Ethereum smart contract ("BulletproofC2") as a dead-drop fallback to fetch replacement C2 server addresses when its primary infrastructure is seized or unreachable.
Arctic Wolf Labs' "Dark Caracal Reloaded: New Malware, Same Hunting Grounds" report (published August 27, 2026) documents a June 2026 intrusion into a Venezuelan communications organization by Dark Caracal, a persistent espionage actor Lookout and EFF first attributed in 2018 to a building belonging to Lebanon's General Directorate of General Security (GDGS) in Beirut. Analysis of 249 related samples spanning January-July 2026 revealed two build profiles of a new modular Go framework, GoCaracal: a lightweight implant (host profiling, AES-GCM encrypted custom-protocol C2, file execution/retrieval, an interactive shell, shellcode loading and process injection, payload download) that establishes a foothold, and an extended build with 34 command handlers (v1.0.1-v1.0.6) that adds targeted file search, Chrome/Brave/Firefox browser-credential harvesting, keylogging, WebRTC-based desktop access, hidden-VNC behavior, cloning of the victim's Chrome profile into a separate hidden session, a SOCKS5 proxy, self-update, and persistence via registry manipulation and a concealed NTUSER.MAN artifact.
GoCaracal runs in parallel with, rather than replacing, an updated Bandook backdoor (~82 obfuscated command handlers, randomized command identifiers replacing the historical sequential @0001-@0136 scheme, browser-credential collection) delivered by a Delphi loader.
The infection chain begins with Spanish-language, financial/tax-themed phishing emails carrying weaponized SVG attachments that embed a Base64-encoded shortened link; opening the SVG redirects the browser through an intermediate redirector to a document-themed staging domain (e.g., getpdfdigital[.]cloud, one of seven identified delivery domains, two of which were previously attributed to the group), which serves a 7-Zip archive containing the lightweight GoCaracal implant (TF-OFICINA004A9.exe). That implant deploys the Delphi loader, which in turn drops Bandook and the extended GoCaracal build.
The headline innovation is GoCaracal's Ethereum-based C2 resilience mechanism: operators deployed a custom Solidity smart contract named "BulletproofC2" (first on Sepolia testnet, later on Ethereum mainnet, from wallet 0x7D321FE277f8c25aaC14aF1BA3Fc34953242052F) whose mutable storage holds a replacement C2 address. After repeated failures against the primary control server, the malware issues eth_getStorageAt JSON-RPC requests to public Ethereum nodes to retrieve that address, letting operators rotate infrastructure via a blockchain transaction rather than redeploying malware to victims. Twenty-three of the 24 identified GoCaracal C2 IPs are hosted on AEZA Group networks; Bandook's C2 sits on AlexHost, a provider previously linked to the group. Beyond the confirmed Venezuelan victim, Arctic Wolf assesses broader Latin American targeting (Brazil, Ecuador, Chile, Colombia, El Salvador, Uruguay) is under investigation, consistent with Dark Caracal's historical reach across 21+ countries and thousands of victims documented by Lookout/EFF since 2012.
MITRE ATT&CK techniques used in TL-2026-2219
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information; T1055 Process Injection; T1564.001 Hidden Files and Directories
Collection
Discovery
T1057 Process Discovery; T1082 System Information Discovery; T1518.001 Security Software Discovery
Command and Control
T1090 Proxy; T1102.001 Dead Drop Resolver; T1573.001 Symmetric Cryptography
defense-impairment
Execution
Persistence
T1547.001 Registry Run Keys / Startup Folder
Credential Access
T1555.003 Credentials from Web Browsers
Initial Access
Affected products and versions in Dark Caracal Deploys New GoCaracal Malware with
- Microsoft — Windows
Vulnerable versions: all supported desktop/server versions - PE-based implant - Google — Chrome
Vulnerable versions: stored credentials/cookies targeted for harvesting - Brave Software — Brave Browser
Vulnerable versions: stored credentials/cookies targeted for harvesting - Mozilla — Firefox
Vulnerable versions: stored credentials/cookies targeted for harvesting
Remediation for Dark Caracal Deploys New GoCaracal Malware with
Immediate actions
- Block the identified GoCaracal/Bandook C2 IP ranges and the seven Spanish-language document-themed phishing-redirect domains at the network perimeter
- Alert on outbound Ethereum JSON-RPC traffic (eth_getStorageAt calls to public nodes) occurring immediately after repeated failed connections to a blocked/known C2 IP - a strong indicator of BulletproofC2 dead-drop fallback lookups
- Hunt Windows endpoints for the identified file hashes and for persistence artifacts under %AppData%\Roaming\<random>\<random>.exe plus concealed NTUSER.MAN files
Workarounds
- Restrict or disable SVG rendering/active-content execution in email clients and browsers for at-risk user populations
- Block or heavily scrutinize the seven identified delivery domains at DNS/web-proxy layer
Longer-term hardening
- Deploy attachment filtering/sandboxing that inspects SVG file content for embedded scripts and redirect URLs rather than trusting the image MIME type
- Harden browser credential stores (OS keychain / Application-Bound Encryption integration) to reduce the value of stolen Chrome, Brave, and Firefox login databases
- Run Spanish-language phishing-simulation and awareness training for finance/tax-adjacent staff, focused on SVG-attachment and shortened-link lures
Timeline of Dark Caracal Deploys New GoCaracal Malware with
- Earliest samples in Arctic Wolf's 249-sample GoCaracal/Bandook analysis set date to this period; the analysis window runs January-July 2026.
- The BulletproofC2 Solidity contract 0x03D605f13A74Bfb6149078122FcF62BD6d8799d8 is deployed, first appearing on Ethereum's Sepolia testnet before a later mainnet deployment.
- Confirmed intrusion into a Venezuelan communications organization using the GoCaracal lightweight and extended builds alongside Bandook - the incident that anchored Arctic Wolf's investigation.
- A new Spanish-language, document-themed domain is registered and begins delivering GoCaracal, one of seven identified phishing-redirect domains (two previously attributed to Dark Caracal).
- Arctic Wolf's sample-analysis window across 249 related GoCaracal/Bandook samples closes, feeding into the August report.
- Arctic Wolf Labs publishes "Dark Caracal Reloaded: New Malware, Same Hunting Grounds," documenting GoCaracal and the Ethereum-based BulletproofC2 fallback mechanism.
- Cyber Security News, Security Affairs, GBHackers, and Cyberpress publicly report on the Arctic Wolf findings, disclosing GoCaracal's Ethereum smart-contract C2 resilience technique.
Sources cited for Dark Caracal Deploys New GoCaracal Malware with
- Dark Caracal Hackers Attacking Victims Using New GoCaracal Malware
- Dark Caracal Reloaded: New Malware, Same Hunting Grounds
- Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback
- Hackers Use Ethereum Smart Contracts to Keep New GoCaracal Malware Connected
- Dark Caracal Deploys New GoCaracal Malware With Ethereum-Based C2 Across Latin America
- Dark Caracal: Cyber-espionage at a Global Scale
- Dark Caracal: You Missed a Spot
Detection coverage for TL-2026-2219
As of 2026-08-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2219 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.