xploitzone.com • 2h
Dark Caracal Deploys GoCaracal Malware with Ethereum-Based C2 Fallback
Dark Caracal, a Lebanon-linked espionage group, has transitioned from its legacy Bandook toolkit to GoCaracal, a Go-based malware framework targeting the Latin American communications sector, specifically within Venezuela. The malware utilizes SVG-based phishing for initial access and implements a high-resilience C2 architecture featuring an Ethereum smart contract fallback mechanism for backup address retrieval. Capabilities include remote shell access, keylogging, browser data exfiltration, and remote desktop control. This evolution significantly increases operational persistence by leveraging decentralized blockchain infrastructure to bypass traditional domain and IP-based takedown efforts.