Dark Caracal Expands Cyber Espionage with GoCaracal Malware Framework

Dark Caracal Expands Cyber Espionage with GoCaracal Malware Framework

First seen 26 Aug 2026, 22:35 UTC Darkreadingwww.techtarget.comwww.lookout.comarcticwolf.com 69.0

Article Content

Browse articles
ThreatCluster

The Lebanon-linked Dark Caracal threat group has introduced a new malware framework called GoCaracal, enhancing its cyber espionage capabilities. Discovered by Arctic Wolf during an investigation into a targeted intrusion in Venezuela, GoCaracal comprises two versions: a lightweight implant for initial access and a more robust version for data harvesting and control. The malware uses a blockchain-based Ethereum database for backup command-and-control server access. Dark Caracal has a history of targeting military personnel, journalists, and activists across 21+ countries since 2012. The group employs phishing and malicious websites to deliver malware, with recent telemetry indicating potential targeting in Latin America, including Brazil and Colombia. The ongoing campaign leverages Spanish-language lures to distribute malicious SVG files. Arctic Wolf researchers are monitoring the situation closely.

Key Points: • Dark Caracal has launched GoCaracal, a new modular malware framework for espionage. • The group targets military, journalists, and activists in over 21 countries since 2012. • Phishing attacks are the primary method for delivering the malware.

Timeline

2026-06-01
Dark Caracal intrusion in Venezuela
Arctic Wolf discovered a targeted intrusion linked to Dark Caracal, leading to the identification of GoCaracal malware.
Darkreading
2026-08-26
GoCaracal malware framework revealed
Arctic Wolf reported on the new GoCaracal framework, detailing its capabilities and targeting methods.
Darkreading
2026-08-26
Lookout and EFF report on Dark Caracal
Lookout and EFF published findings on Dark Caracal's global espionage campaigns and the use of Pallas malware.
www.lookout.com