Dark Caracal Unveils GoCaracal Malware for Cyber Espionage

Dark Caracal Unveils GoCaracal Malware for Cyber Espionage

First seen 26 Aug 2026, 22:35 UTC Darkreadingwww.techtarget.comwww.lookout.comScworldGround.News+7 75.5

Article Content

Browse articles
ThreatCluster

The Lebanon-linked Dark Caracal threat group has introduced a new malware framework named GoCaracal, enhancing its cyberespionage capabilities. Discovered by Arctic Wolf during an intrusion investigation in Venezuela, GoCaracal features two versions: a lightweight implant for initial access and a robust version for intelligence gathering. This malware employs a novel technique by using Ethereum blockchain as a backup for command-and-control (C2) server discovery. Dark Caracal has been active since at least 2012, targeting military, government, and various organizations across Latin America. The group continues to utilize established tactics, including phishing and malicious websites, to deliver malware. The current campaign is focused on Spanish-speaking countries, with potential victims identified in Brazil, Ecuador, and Colombia. The sophistication of GoCaracal poses a significant risk of persistent access for intelligence gathering.

Key Points: • Dark Caracal has launched GoCaracal, a new modular malware framework. • The malware utilizes Ethereum blockchain for backup C2 server discovery. • Targeted campaigns are ongoing in multiple Latin American countries.

Timeline

2026-06-01
GoCaracal malware discovered
Arctic Wolf identified GoCaracal during an investigation into a targeted attack on a Venezuelan communications organization.
Darkreading
2026-08-26
Dark Caracal's capabilities upgraded
The new GoCaracal framework provides broader data theft capabilities and persistent access to compromised systems.
Ground.News
2026-08-27
Ongoing cyberespionage campaign
Dark Caracal continues its established targeting tactics in Latin America, focusing on Spanish-speaking organizations.
Scworld