Threat reportMalwareTL-2026-2219

Dark Caracal Deploys New GoCaracal Malware with Ethereum-Based C2 Resilience in Venezuela Breach

highACTIVE

Dark Caracal Deploys New GoCaracal Malware with (TL-2026-2219), also tracked as Dark Caracal Reloaded, is a high-severity malware campaign, first published 2026-08-29. It is attributed to Dark Caracal (Lebanon) with medium confidence, affects Microsoft Windows, maps to 16 MITRE ATT&CK techniques (T1021.005, T1027, T1055), and is covered by 9 detection rules and 30 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
16MITRE ATT&CK
Actors
1Dark Caracal
Detection rules
9SPL · KQL · Sigma
IOCs
30Indicators of compromise

Key facts for TL-2026-2219

Threat ID
TL-2026-2219
Also known as
Dark Caracal Reloaded
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Dark Caracal
Attribution confidence
MEDIUM
Nation-state nexus
Lebanon
Motivation
ESPIONAGE
Target sectors
telecoms
Target regions
Latin America
Detection rules
9
Indicators of compromise
30

Malware and tooling in Dark Caracal Deploys New GoCaracal Malware with

Malware and tooling: Bandook, GoCaracal, 0x03D605f13A74Bfb6149078122FcF62BD6d8799d8, 0x04aB453494381E60171BE04Ea6BE6E7C44EafAfd, 0x7D321FE277f8c25aaC14aF1BA3Fc34953242052F, 0xD7635f31620772882a6712472a6278c53247Bc44, 0xf165F26300BF65DFaC78BC9557326bDbB3C6d33C

How Dark Caracal Deploys New GoCaracal Malware with works

Lebanon-linked cyberespionage group Dark Caracal (G0070) deployed a previously undocumented Go-based malware framework, GoCaracal, alongside its legacy Bandook backdoor in a confirmed June 2026 breach of a Venezuelan communications organization. The extended GoCaracal build queries a custom Ethereum smart contract ("BulletproofC2") as a dead-drop fallback to fetch replacement C2 server addresses when its primary infrastructure is seized or unreachable.

Arctic Wolf Labs' "Dark Caracal Reloaded: New Malware, Same Hunting Grounds" report (published August 27, 2026) documents a June 2026 intrusion into a Venezuelan communications organization by Dark Caracal, a persistent espionage actor Lookout and EFF first attributed in 2018 to a building belonging to Lebanon's General Directorate of General Security (GDGS) in Beirut. Analysis of 249 related samples spanning January-July 2026 revealed two build profiles of a new modular Go framework, GoCaracal: a lightweight implant (host profiling, AES-GCM encrypted custom-protocol C2, file execution/retrieval, an interactive shell, shellcode loading and process injection, payload download) that establishes a foothold, and an extended build with 34 command handlers (v1.0.1-v1.0.6) that adds targeted file search, Chrome/Brave/Firefox browser-credential harvesting, keylogging, WebRTC-based desktop access, hidden-VNC behavior, cloning of the victim's Chrome profile into a separate hidden session, a SOCKS5 proxy, self-update, and persistence via registry manipulation and a concealed NTUSER.MAN artifact.

GoCaracal runs in parallel with, rather than replacing, an updated Bandook backdoor (~82 obfuscated command handlers, randomized command identifiers replacing the historical sequential @0001-@0136 scheme, browser-credential collection) delivered by a Delphi loader.

The infection chain begins with Spanish-language, financial/tax-themed phishing emails carrying weaponized SVG attachments that embed a Base64-encoded shortened link; opening the SVG redirects the browser through an intermediate redirector to a document-themed staging domain (e.g., getpdfdigital[.]cloud, one of seven identified delivery domains, two of which were previously attributed to the group), which serves a 7-Zip archive containing the lightweight GoCaracal implant (TF-OFICINA004A9.exe). That implant deploys the Delphi loader, which in turn drops Bandook and the extended GoCaracal build.

The headline innovation is GoCaracal's Ethereum-based C2 resilience mechanism: operators deployed a custom Solidity smart contract named "BulletproofC2" (first on Sepolia testnet, later on Ethereum mainnet, from wallet 0x7D321FE277f8c25aaC14aF1BA3Fc34953242052F) whose mutable storage holds a replacement C2 address. After repeated failures against the primary control server, the malware issues eth_getStorageAt JSON-RPC requests to public Ethereum nodes to retrieve that address, letting operators rotate infrastructure via a blockchain transaction rather than redeploying malware to victims. Twenty-three of the 24 identified GoCaracal C2 IPs are hosted on AEZA Group networks; Bandook's C2 sits on AlexHost, a provider previously linked to the group. Beyond the confirmed Venezuelan victim, Arctic Wolf assesses broader Latin American targeting (Brazil, Ecuador, Chile, Colombia, El Salvador, Uruguay) is under investigation, consistent with Dark Caracal's historical reach across 21+ countries and thousands of victims documented by Lookout/EFF since 2012.

MITRE ATT&CK techniques used in TL-2026-2219

Lateral Movement

T1021.005 VNC

Defense Evasion

T1027 Obfuscated Files or Information; T1055 Process Injection; T1564.001 Hidden Files and Directories

Collection

T1056.001 Keylogging

Discovery

T1057 Process Discovery; T1082 System Information Discovery; T1518.001 Security Software Discovery

Command and Control

T1090 Proxy; T1102.001 Dead Drop Resolver; T1573.001 Symmetric Cryptography

defense-impairment

T1112 Modify Registry

Execution

T1204.002 Malicious File

Persistence

T1547.001 Registry Run Keys / Startup Folder

Credential Access

T1555.003 Credentials from Web Browsers

Initial Access

T1566.001 Spearphishing Attachment

Affected products and versions in Dark Caracal Deploys New GoCaracal Malware with

  • Microsoft — Windows
    Vulnerable versions: all supported desktop/server versions - PE-based implant
  • Google — Chrome
    Vulnerable versions: stored credentials/cookies targeted for harvesting
  • Brave Software — Brave Browser
    Vulnerable versions: stored credentials/cookies targeted for harvesting
  • Mozilla — Firefox
    Vulnerable versions: stored credentials/cookies targeted for harvesting

Remediation for Dark Caracal Deploys New GoCaracal Malware with

Immediate actions

  • Block the identified GoCaracal/Bandook C2 IP ranges and the seven Spanish-language document-themed phishing-redirect domains at the network perimeter
  • Alert on outbound Ethereum JSON-RPC traffic (eth_getStorageAt calls to public nodes) occurring immediately after repeated failed connections to a blocked/known C2 IP - a strong indicator of BulletproofC2 dead-drop fallback lookups
  • Hunt Windows endpoints for the identified file hashes and for persistence artifacts under %AppData%\Roaming\<random>\<random>.exe plus concealed NTUSER.MAN files

Workarounds

  • Restrict or disable SVG rendering/active-content execution in email clients and browsers for at-risk user populations
  • Block or heavily scrutinize the seven identified delivery domains at DNS/web-proxy layer

Longer-term hardening

  • Deploy attachment filtering/sandboxing that inspects SVG file content for embedded scripts and redirect URLs rather than trusting the image MIME type
  • Harden browser credential stores (OS keychain / Application-Bound Encryption integration) to reduce the value of stolen Chrome, Brave, and Firefox login databases
  • Run Spanish-language phishing-simulation and awareness training for finance/tax-adjacent staff, focused on SVG-attachment and shortened-link lures

Timeline of Dark Caracal Deploys New GoCaracal Malware with

  • Earliest samples in Arctic Wolf's 249-sample GoCaracal/Bandook analysis set date to this period; the analysis window runs January-July 2026.
  • The BulletproofC2 Solidity contract 0x03D605f13A74Bfb6149078122FcF62BD6d8799d8 is deployed, first appearing on Ethereum's Sepolia testnet before a later mainnet deployment.
  • Confirmed intrusion into a Venezuelan communications organization using the GoCaracal lightweight and extended builds alongside Bandook - the incident that anchored Arctic Wolf's investigation.
  • A new Spanish-language, document-themed domain is registered and begins delivering GoCaracal, one of seven identified phishing-redirect domains (two previously attributed to Dark Caracal).
  • Arctic Wolf's sample-analysis window across 249 related GoCaracal/Bandook samples closes, feeding into the August report.
  • Arctic Wolf Labs publishes "Dark Caracal Reloaded: New Malware, Same Hunting Grounds," documenting GoCaracal and the Ethereum-based BulletproofC2 fallback mechanism.
  • Cyber Security News, Security Affairs, GBHackers, and Cyberpress publicly report on the Arctic Wolf findings, disclosing GoCaracal's Ethereum smart-contract C2 resilience technique.

Sources cited for Dark Caracal Deploys New GoCaracal Malware with

Detection coverage for TL-2026-2219

As of 2026-08-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2219 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
30 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats