Dark Caracal Adds GoCaracal to Its Espionage Arsenal
APT

Illustrative image generated with AI

Dark Caracal Adds GoCaracal to Its Espionage Arsenal

GoCaracal malware by Dark Caracal discovered, with dual variants and Ethereum-based C2 backup for advanced espionage operations.

Text generated by artificial intelligence, published without human review. AI transparency

Discovery in Venezuela and the New Framework

In mid-2026, during a targeted intrusion in Venezuela, Arctic Wolf researchers identified a previously unknown malware framework tracked as GoCaracal. The activity is attributed to Dark Caracal, a cyber espionage group linked to Lebanon's General Directorate of General Security (GDGS).

Analysis of approximately 250 samples identified two distinct versions of the malware. One is a lightweight implant for initial access and downloading additional payloads. The other is a more extensive build designed for intelligence collection and maintaining interactive control over compromised systems.

The June 2026 intrusion at a Venezuelan communications organization revealed GoCaracal alongside an updated version of Bandook, a commercial Windows RAT in use since 2007. Arctic Wolf interprets this as complementary use: the two tools coexist without one immediately replacing the other.

Two Versions for Access and Control

The two GoCaracal variants serve different operational needs. The lightweight version handles initial access: it installs itself, profiles the host, communicates in encrypted form with the command-and-control server, and downloads additional modules. It is the first link in the chain, designed to remain unnoticed.

The extended version, on the other hand, implements full data collection capabilities: credential theft, keylogging, remote shell, and file exfiltration. It is a long-term intelligence tool capable of ensuring persistence and direct interaction with the infected machine.

The replacement of the previous AsioGate malware—previously used for initial access and post-compromise activity—with GoCaracal indicates a rotation of tools. AsioGate is no longer the primary vector: its functions have been absorbed by the new framework, which offers greater modularity and evasion capabilities.

Ethereum as a Fallback Channel

The most distinctive feature of the extended GoCaracal version is the use of a public Ethereum blockchain-based database as a backup source for locating command-and-control servers.

If the primary C2 infrastructure becomes unreachable, the malware queries the blockchain and retrieves alternative addresses. This mechanism makes takedown much more difficult: even seizing the primary domains, attackers maintain a decentralized and public recovery channel.

The use of Ethereum signals growing sophistication. It is not entirely new in the malware landscape, but for a state-sponsored espionage group it represents a leap in operational resilience. Attempts to take down C2 infrastructure become less effective when the fallback point is an immutable blockchain.

Infrastructure and Spanish-Language Lures

The infrastructure associated with the June 2026 intrusion is part of a larger cluster of Spanish-language document-themed domains. These domains are used to distribute malicious SVG files and subsequent payloads.

SVGs are not simple images: they can contain scripts that, once opened, download and execute malicious code. The choice of document lures—invoices, forms, financial documents—aims to convince the user to open the attached file or visit the controlled site.

Telemetry collected by Arctic Wolf indicates possible targeting in Brazil, Ecuador, Uruguay, El Salvador, Colombia, and Chile, in addition to the already confirmed Venezuela. Attribution to Dark Caracal, however, is not uniform across all observed activity: some signals may belong to related campaigns but cannot be conclusively attributed to the group.

Dark Caracal: Who the Group Is

Dark Caracal has been active since at least 2012. Its campaigns have targeted military and government personnel, companies, journalists, activists, lawyers, healthcare professionals, and educational institutions. Known tactics include phishing, malicious websites, and trojanized mobile applications, with theft of documents, communications, credentials, photos, and other sensitive data.

The group's arsenal includes Pallas, a custom-built toolkit for stealing data from Android devices, and a customized version of Bandook, a commercial Windows RAT used by multiple actors since 2007. The combination of mobile and desktop tools enables coverage of a wide range of devices.

The addition of GoCaracal—actively developed throughout 2026—consolidates operational capability. The malware has evolved from relatively basic functions of encrypted communication, host profiling, and code execution to a modular framework with reusable components, interactive shells, and techniques to evade antivirus and other security mechanisms.

Impact and Defensive Actions

The severity of this activity is not quantified by a CVSS score, since it is not a single vulnerability but a malware framework for long-term espionage. The operational impact for targeted organizations is high: establishing and maintaining a persistent, undetected foothold enables silent collection of intelligence on people, operations, and relationships.

Exfiltrated data may include confidential documents, internal communications, access credentials, keylogs, and content from Android devices via Pallas. Interactive remote control allows attackers to move laterally and prepare future actions.

Arctic Wolf has released indicators of compromise and detection information. Organizations can use these IOCs for detection and threat hunting: search logs for the presence of domains, sample hashes, or network peculiarities associated with GoCaracal, Bandook, and Pallas.

The source does not describe further detailed technical mitigations. The principle of defense in depth remains valid: network segmentation, endpoint monitoring, suspicious process control, and user training on the risks of SVG attachments and Spanish-language document lures.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsDark CaracalGoCaracalmalwareespionageEthereum blockchainC2 infrastructureVenezuelacyber espionage
Back to home