Dark Caracal Introduces GoCaracal Malware Utilizing Ethereum for Stealth Control
Dark Caracal launched GoCaracal, a malware framework that uses Ethereum for resilient command-and-control despite server disruptions. This innovation poses significant challenges for cybersecurity defenses, necessitating new strategies to address evolving threats.

The cyberespionage group Dark Caracal has launched GoCaracal, a malware framework utilizing Ethereum for fallback command-and-control operations. The framework is linked to a June 2026 breach in Venezuela, initiated through phishing campaigns targeting financial victims.
GoCaracal features two versions: one for reconnaissance and another with extended capabilities, including file searching and remote access. The framework employs an Ethereum-based smart contract named BulletproofC2 to retrieve server addresses when primary servers are compromised.
This approach complicates defense strategies, as traditional takedowns may be ineffective against its resilient architecture. Analysts recommend enhanced monitoring of blockchain activities alongside standard cybersecurity measures.




Comments