# Dark Caracal Deploys New GoCaracal Malware with Ethereum-Based C2 Resilience in Venezuela Breach

> Lebanon-linked cyberespionage group Dark Caracal (G0070) deployed a previously undocumented Go-based malware framework, GoCaracal, alongside its legacy Bandook backdoor in a confirmed June 2026 breach of a Venezuelan communications organization. The extended GoCaracal build queries a custom Ethereum smart contract ("BulletproofC2") as a dead-drop fallback to fetch replacement C2 server addresses when its primary infrastructure is seized or unreachable.

- **Published:** 2026-08-29T00:00:00Z
- **Last reviewed:** 2026-08-29T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2219
- **ID:** TL-2026-2219
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Dark Caracal (Lebanon)
- **Detections:** 9 · **IOCs:** 30 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Arctic Wolf Labs' "Dark Caracal Reloaded: New Malware, Same Hunting Grounds" report (published August 27, 2026) documents a June 2026 intrusion into a Venezuelan communications organization by Dark Caracal, a persistent espionage actor Lookout and EFF first attributed in 2018 to a building belonging to Lebanon's General Directorate of General Security (GDGS) in Beirut. Analysis of 249 related samples spanning January-July 2026 revealed two build profiles of a new modular Go framework, GoCaracal: a lightweight implant (host profiling, AES-GCM encrypted custom-protocol C2, file execution/retrieval, an interactive shell, shellcode loading and process injection, payload download) that establishes a foothold, and an extended build with 34 command handlers (v1.0.1-v1.0.6) that adds targeted file search, Chrome/Brave/Firefox browser-credential harvesting, keylogging, WebRTC-based desktop access, hidden-VNC behavior, cloning of the victim's Chrome profile into a separate hidden session, a SOCKS5 proxy, self-update, and persistence via registry manipulation and a concealed NTUSER.MAN artifact.

GoCaracal runs in parallel with, rather than replacing, an updated Bandook backdoor (~82 obfuscated command handlers, randomized command identifiers replacing the historical sequential @0001-@0136 scheme, browser-credential collection) delivered by a Delphi loader.

The infection chain begins with Spanish-language, financial/tax-themed phishing emails carrying weaponized SVG attachments that embed a Base64-encoded shortened link; opening the SVG redirects the browser through an intermediate redirector to a document-themed staging domain (e.g., getpdfdigital[.]cloud, one of seven identified delivery domains, two of which were previously attributed to the group), which serves a 7-Zip archive containing the lightweight GoCaracal implant (TF-OFICINA004A9.exe). That implant deploys the Delphi loader, which in turn drops Bandook and the extended GoCaracal build.

The headline innovation is GoCaracal's Ethereum-based C2 resilience mechanism: operators deployed a custom Solidity smart contract named "BulletproofC2" (first on Sepolia testnet, later on Ethereum mainnet, from wallet 0x7D321FE277f8c25aaC14aF1BA3Fc34953242052F) whose mutable storage holds a replacement C2 address. After repeated failures against the primary control server, the malware issues eth_getStorageAt JSON-RPC requests to public Ethereum nodes to retrieve that address, letting operators rotate infrastructure via a blockchain transaction rather than redeploying malware to victims. Twenty-three of the 24 identified GoCaracal C2 IPs are hosted on AEZA Group networks; Bandook's C2 sits on AlexHost, a provider previously linked to the group. Beyond the confirmed Venezuelan victim, Arctic Wolf assesses broader Latin American targeting (Brazil, Ecuador, Chile, Colombia, El Salvador, Uruguay) is under investigation, consistent with Dark Caracal's historical reach across 21+ countries and thousands of victims documented by Lookout/EFF since 2012.

## MITRE ATT&CK

- T1566.001 Spearphishing Attachment
- T1204.002 Malicious File
- T1055 Process Injection
- T1547.001 Registry Run Keys / Startup Folder
- T1112 Modify Registry
- T1027 Obfuscated Files or Information
- T1564.001 Hidden Files and Directories
- T1082 System Information Discovery
- T1057 Process Discovery
- T1518.001 Security Software Discovery
- T1555.003 Credentials from Web Browsers
- T1056.001 Keylogging
- T1021.005 VNC
- T1573.001 Symmetric Cryptography
- T1102.001 Dead Drop Resolver
- T1090 Proxy

## Sources

- [Dark Caracal Hackers Attacking Victims Using New GoCaracal Malware](https://cybersecuritynews.com/dark-caracal-hackers/)
- [Dark Caracal Reloaded: New Malware, Same Hunting Grounds](https://arcticwolf.com/resources/blog/dark-caracal-reloaded-new-malware-same-hunting-grounds/)
- [Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback](https://securityaffairs.com/197948/apt/dark-caracal-deploys-new-go-malware-with-ethereum-based-c2-fallback.html)
- [Hackers Use Ethereum Smart Contracts to Keep New GoCaracal Malware Connected](https://gbhackers.com/gocaracal-malware-attack/)
- [Dark Caracal Deploys New GoCaracal Malware With Ethereum-Based C2 Across Latin America](https://cyberpress.org/dark-caracal-debuts-gocaracal/)
- [Dark Caracal: Cyber-espionage at a Global Scale](https://www.lookout.com/documents/reports/lookout-dark-caracal-20180118-us.pdf)
- [Dark Caracal: You Missed a Spot](https://www.eff.org/deeplinks/2020/12/dark-caracal-you-missed-spot)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2219
