All incidents

Dark Caracal deploys GoCaracal malware with Ethereum-based C2

malwareopenAug 26, 2026 — Aug 27, 2026
Dark Caracal's GoCaracal malware uses Ethereum C2 in Venezuela

DARK Caracal has unveiled a new Go‑based malware family dubbed GoCaracal that was spotted targeting a Venezuelan communications organisation according to Arctic Wolf Labs. The campaign was first observed on 26 August 2026 and continues to be active, with the attackers using the malware to establish persistent access while preparing for data theft.

Infection begins with a phishing email that contains a malicious SVG file; when the recipient opens the attachment the SVG executes JavaScript that contacts an attacker‑controlled server as reported by Security Affairs. This initial contact downloads the GoCaracal payload, which is written in the Go programming language. The malware then checks in with its primary command and control infrastructure.

GoCaracal comes in two distinct builds. A lightweight version

Intelligence briefing updated Aug 27, 2026

Dark Caracal
Root sourcearcticwolf.com
Timeline Coverage

Swipe to explore timeline