# GoCaracal Malware Targets Venezuelan Communications Firm Using Ethereum Smart Contracts

*Published August 28, 2026*
*Source: [https://thehackernews.com/2026/08/gocaracal-malware-uses-ethereum-smart.html](https://thehackernews.com/2026/08/gocaracal-malware-uses-ethereum-smart.html)*

## Executive Summary

Arctic Wolf discovered GoCaracal malware, linked to Dark Caracal, targeting a Venezuelan communications firm. The malware employs Ethereum smart contracts for resilient command-and-control, allowing operators to modify server addresses without redistributing the malware.

## Article

Security researchers at Arctic Wolf have identified a new malware framework called GoCaracal, linked to the notorious Dark Caracal group. This discovery arose from a cyber intrusion in June 2026 at a communications company in Venezuela. The malware, which is written in Go, provides attackers with remote shell access and the ability to execute payloads. It comes in two profiles: a lightweight version and a more comprehensive extended version. The lightweight profile offers host profiling, an encrypted command-and-control channel, and payload execution. The extended version expands these capabilities to include browser data theft, keylogging, remote desktop control, and SOCKS5 proxying.

The deployment of GoCaracal was accompanied by the Bandook malware, a tool previously used by Dark Caracal. Although both were employed simultaneously, there is currently no evidence suggesting GoCaracal is replacing Bandook. Arctic Wolf's assessment, linking the activity to Dark Caracal, was based on several factors such as the use of the Bandook malware, Spanish-language financial lures, and a focus on Latin American targets. The analysis also highlighted the use of phishing as a delivery vector, despite the original phishing email not being recovered.

A notable feature of GoCaracal is its use of Ethereum smart contracts to maintain its command-and-control communications. If the primary server becomes unreachable, the malware queries an Ethereum JSON-RPC endpoint to obtain a replacement server address, reducing reliance on a single access point. This strategy allows operators to update the server address without needing to distribute a new malware version.

Dark Caracal has a history of activity in Latin America. While Arctic Wolf identified related infrastructure in several countries, including Brazil and Ecuador, they did not confirm these locations as victim countries. The full scope of the campaign and the effectiveness of the Ethereum fallback remain unclear, as Arctic Wolf has not confirmed whether this mechanism was seen in action during the intrusion.
