New GoCaracal Malware Uses Ethereum Blockchain to Stay in Contact With Hackers
Cybersecurity firm Arctic Wolf has identified a new malware framework called GoCaracal that adds a novel twist to how attackers keep control of infected systems. Written in the Go programming language, the malware uses Ethereum blockchain infrastructure as a fallback method for retrieving the location of its command-and-control (C2) servers if its primary channels are blocked or taken down.
Using blockchain networks for backup communication is an emerging tactic among cybercriminals, as it makes it far more difficult for defenders to disrupt an attack by simply blocking known malicious IP addresses or domains. Because blockchain data is decentralised and publicly distributed, taking down this kind of backup channel is far harder than shutting down a traditional server.
The malware was discovered during an intrusion in June 2026 targeting a communications organisation in Venezuela. While this specific attack was overseas, the techniques used by GoCaracal reflect a broader trend of attackers adopting more resilient, harder-to-block infrastructure — a development that security teams everywhere, including in Australia, should be aware of.