
GoCaracal Malware Leverages Ethereum Smart Contract for C2 Resilience
Researchers from Arctic Wolf have identified a previously undocumented malware framework, GoCaracal, deployed in June 2026 against an unnamed communications organization in Venezuela. The threat actors, linked with medium confidence to the Dark Caracal group, utilize an Ethereum smart contract to dynamically fetch replacement command-and-control addresses, enhancing C2 resilience against traditional blocking measures. The malware provides remote shell access and payload execution, with an extended profile capable of browser data theft, keylogging, and remote desktop control.
