Threat Intelligence

New GoCaracal Malware Uses Ethereum Blockchain to Hide Its Command Servers

The Hacker News · 27 Aug 2026
Key Takeaway Small businesses should ensure endpoint detection tools and network monitoring are in place, since attackers are increasingly using resilient, hard-to-block infrastructure like blockchain-based command servers.

Security researchers at Arctic Wolf have identified a previously undocumented malware framework called GoCaracal, used in a June 2026 intrusion against a communications company in Venezuela. The malware is linked, with medium confidence, to the Dark Caracal threat group, a hacking operation known for espionage-style attacks.

What makes GoCaracal notable is its use of an Ethereum smart contract to fetch replacement command-and-control (C2) server addresses. This technique makes the malware harder to disrupt, as security teams can't simply block a single server address to shut down the attack — the blockchain-based lookup allows operators to quickly redirect traffic to new infrastructure if the original is taken down.

Beyond basic remote shell access and the ability to run additional payloads, an extended version of the malware includes browser data theft, keystroke logging, and remote desktop control. This gives attackers a full toolkit for stealing sensitive information and maintaining hands-on access to compromised systems, raising the stakes for organisations that may be targeted.

malware Dark Caracal cyber threat intelligence

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.