GoCaracal Malware Uses Ethereum Smart Contract for C2 Backup
Blocking a malware’s command server is usually insufficient if a new address can be fetched straight from the blockchain. Arctic Wolf specialists have discovered a previously unknown modular malware belonging to the Dark Caracal group, dubbed GoCaracal, which can re-establish contact with its operators through an Ethereum smart contract.
Discovery in a Venezuelan Intrusion
GoCaracal was found during an investigation into a targeted campaign against a telecommunications organization in Venezuela in June 2026. Arctic Wolf links the operation, with medium confidence, to Dark Caracal, which had previously been associated with Lebanon’s General Directorate of General Security. For many years, the group has taken an interest in government structures, companies, journalists, and activists.
A Familiar Infection Chain
The infection chain preserved a scheme familiar from Dark Caracal. Victims were sent Spanish-language lures on financial and tax themes bearing malicious SVG files. Inside was an encoded shortened link that, through several redirects, led to a site under the attackers’ control. The site served an archive containing a lightweight version of GoCaracal.
Two Builds of GoCaracal
An analysis of 249 samples showed that the developers maintain two variants of GoCaracal. The compact version gathers information about the computer, establishes an encrypted connection with the command server, runs commands, downloads files, and injects code into other processes. This variant is needed above all to gain a foothold in the system and deliver additional components.
The extended build is designed for sustained espionage and contains 34 command handlers. GoCaracal can search for and download files, harvest browser data, log keystrokes, launch hidden browser sessions, provide remote desktop access via WebRTC, and turn the infected computer into a SOCKS5 proxy. Development ran at least from January to July 2026, and the feature set grew steadily from a simple implant into a full-fledged remote-control tool.
An Unusual Blockchain Mechanism
An unusual mechanism appeared in the extended builds over the summer. After several failed attempts to reach the primary command server, GoCaracal can turn to a public Ethereum node and read a value from a predefined smart contract. The discovered contract, BulletproofC2, stores the address of a fallback server, which the operator can change with a new transaction.
The command traffic itself does not pass through Ethereum. The blockchain serves as a resilient directory holding the current infrastructure address. After a server change, already-infected computers require no new version of GoCaracal, and blocking a single domain or IP address does not deprive the operators of the ability to restore contact. Arctic Wolf also discovered several similar contracts, first tested on the Sepolia test network and then deployed on the Ethereum mainnet.
Bandook Runs Alongside
In the same operation, Dark Caracal continued to employ the long-known remote-access trojan Bandook. The fresh version received randomised command identifiers in place of the former sequential numbering, along with obfuscated component names, which complicates searches based on old signatures. The malware can also extract credentials from Chrome, Brave, and Firefox.
A Modernised Toolkit Across Latin America
Arctic Wolf does not yet regard GoCaracal as a replacement for Bandook. Both programs operated in parallel, though the capabilities of the new framework largely overlap with the functions of the older trojan. The specialists also found artifacts and infrastructure associated with the campaign in Brazil, Ecuador, Chile, Colombia, El Salvador, and Uruguay, so Dark Caracal’s activity likely spans a significant part of Latin America.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.