Skip to content
Dark Caracal Adds New Malware to Cyber Espionage Arsenal

Dark Caracal Adds New Malware to Cyber Espionage Arsenal

Darkreading •Jai Vijayan • August 26, 2026

Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa, the Asia Pacific, Europe, and Latin America.

GoCaracal is a new modular malware framework that broadens Dark Caracal's capabilities to steal data and maintain access to victims.

The Lebanon-linked Dark Caracal threat group has upgraded its cyberespionage arsenal with a previously unknown malware framework that gives the threat actor broader capabilities for stealing data and maintaining persistent access to compromised systems.

Researchers at Arctic Wolf discovered the new malware when investigating a targeted intrusion in Venezuela and are tracking the new framework as GoCaracal.

In a report this week, the security vendor said its analysis of some 250 samples of the malware revealed the threat actor is using two versions of GoCaracal. One of them is a lightweight implant for initial access and downloading additional payloads while the other is a more substantial build for harvesting intelligence and maintaining interactive control on compromised systems. The extended version of GoCaracal uses a public blockchain-based Ethereum database as a backup source for finding command-and-control servers if its main C2 infrastructure becomes unavailable.

"The infrastructure associated with the June 2026 intrusion forms part of a broader cluster of Spanish-language, document-themed domains used to deliver malicious SVG files and downstream payloads," Arctic Wolf researchers wrote in the report.

Dark Caracal is a long-running cyber-espionage operation that researchers have previously linked to Lebanon's General Directorate of General Security (GDGS). The group has been active since at least 2012 and has been associated with intelligence gathering operations that have targeted a broad range of organizations and individuals including military and government personnel, businesses, journalists, activists, lawyers, medical professionals and educational institutions.

The group has used a variety of tactics such as phishing, malicious websites and Trojanized mobile applications to deliver malware and to steal documents, communications, credentials, photos and other sensitive data. Dark Caracal's malware toolkit includes Pallas a custom-developed toolkit for stealing data from Android devices and a custom version of Bandook, a commercially available Windows remote access Trojan that multiple threat actors have been using since 2007.

According to Arctic Wolf, Dark Caracal appears to be maintaining its established targeting and delivery tactics in its ongoing Latin American campaign, using Spanish-language, financial, and document-themed lures to deliver malicious SVG files and subsequent payloads. The security company said its telemetry points to potential targeting in Brazil, Ecuador, Uruguay, El Salvador, Colombia and Chile, although the evidence linking all of the activity to Dark Caracal is not equally strong.

In the June 2026 intrusion that Arctic Wolf investigated at a Venezuelan communications organization, researchers found GoCaracal deployed alongside an updated version of Bandook. Arctic Wolf interpreted that as a sign that Dark Caracal actors are using GoCaracal to complement Bandook's capabilities rather than to replace it outright, at least for the moment. The threat actors, however, appear to have replaced their earlier AsioGate malware for initial access and post-compromise activities with Dark Caracal, which they are using for file collection, credential theft, keystroke logging, remote shell access and other intelligence-gathering activities.

GoCaracal is malware the threat actor has been actively developing throughout 2026, Arctic Wolf said. The framework started with relatively basic capabilities for encrypted communications, host profiling and code execution and has evolved into a modular malware tool with reusable components, interactive shells, and features for evading antivirus tools and other security mechanisms. The malware's support for an Ethereum-based C2 fallback is indication of its growing sophistication and resilience against takedown attempts.

For organizations in the crosshairs of cyber-espionage groups like Dark Caracal, the bigger risk often has to do with the attackers establishing and maintaining a persistent, undetected foothold in the target environment. The objective is not necessarily to steal data immediately, but to quietly gather intelligence an organization's people, operations and relationships for potential use in future attacks. Arctic Wolf has provided indicators of compromise and other information that organizations can use to for or detect signs of malicious activity tied to Dark Caracal activity.

Illinois-based Jai Vijayan is a veteran, award-winning technology journalist with more than 25 years of experience covering cybersecurity. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies.

Over the course of his career, Jai has written news stories, feature articles, survey reports, white papers, and e-books for enterprise and technology audiences. He has also moderated panel discussions and executive roundtables featuring CISOs, security researchers, and industry leaders.

Jai previously served as senior editor at Computerworld, where he covered information security and data-privacy issues. His work has also appeared in CSO Online, InformationWeek, The Christian Science Monitor Passcode, The Economic Times, and other publications.

His work has earned multiple industry honors, including a Joint ASBPE Excellence Award for Best Coverage of Government IT, and a Joint Jesse H. Neal Award for wireless LAN security coverage. Jai holds a Master’s degree in statistics from Bangalore University, and studied broadcasting and electronic communication at Marquette University in Milwaukee.

The State of Cloud Security: The Latest Challenges

How Organizations Are Managing Incident Response

How Enterprises Are Developing Secure Applications

Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy

Essential News & Insights from Black Hat USA 2025

Cloud Incident Response: Forensics in Distributed Environments

Beyond the Login: Key Considerations for Evaluating Identity Security

SASE Pivot and Trends 2026: A Gartner Keynote

What Every Enterprise Should Know Securing Cloud Assets In the Age of AI

The Dos and Don'ts of a Cybersecurity Awareness Month People Actually Remember