DARK Caracal, a cyberespionage group linked to Lebanon, has deployed a new Go-based malware known as GoCaracal against a Venezuelan communications organization, according to researchers from Arctic Wolf Labs. This malware, an evolution of the Bandook toolkit, features an Ethereum-based fallback for command and control (C2) communications, enhancing its resilience. The infection vector involves phishing emails with malicious SVG attachments leading to a known attacker site.
GoCaracal operates with two profiles: a lightweight version for access and payload delivery and an extended version for extensive post-compromise activities, such as file management and credential theft. It utilizes Ethereum smart contracts to dynamically update C2 addresses, allowing for seamless operational continuity. The malware has been traced across various Latin American countries, indicating a sustained focus on regional targets. Arctic Wolf's analysis suggests that Dark Caracal is modernizing its toolkit while maintaining established operational practices.