New Malware 'GoCaracal' Uses Ethereum Blockchain as Backup Hacking Channel
Researchers at Arctic Wolf have identified a new malware framework, dubbed GoCaracal, that uses Ethereum blockchain infrastructure as a resilient backup channel for command-and-control (C2) communications. Written in the Go programming language, the malware was observed during a June 2026 cyberattack targeting a communications organisation in Venezuela.
By leveraging an Ethereum smart contract, attackers can maintain access to infected systems even if their primary servers are taken down by defenders or law enforcement. This makes the malware harder to fully disable, since blockchain-based infrastructure is decentralised and difficult to seize or block using traditional takedown methods.
While this specific campaign targeted a large organisation overseas, the technique highlights a broader trend of cybercriminals adopting blockchain tools to make their attacks more resilient. Australian businesses should be aware that traditional network defences, like blocking known malicious IP addresses, may not be enough to stop threats that use decentralised backup channels.