New GoCaracal Malware Uses Ethereum Blockchain to Hide Its Command Servers
Security researchers at Arctic Wolf have identified a previously undocumented malware framework called GoCaracal, used in a June 2026 intrusion against a communications company in Venezuela. The malware is linked, with medium confidence, to the Dark Caracal threat group, a hacking operation known for espionage-style attacks.
What makes GoCaracal notable is its use of an Ethereum smart contract to fetch replacement command-and-control (C2) server addresses. This technique makes the malware harder to disrupt, as security teams can't simply block a single server address to shut down the attack — the blockchain-based lookup allows operators to quickly redirect traffic to new infrastructure if the original is taken down.
Beyond basic remote shell access and the ability to run additional payloads, an extended version of the malware includes browser data theft, keystroke logging, and remote desktop control. This gives attackers a full toolkit for stealing sensitive information and maintaining hands-on access to compromised systems, raising the stakes for organisations that may be targeted.