Overview
- Arctic Wolf published its report Thursday after investigating a June intrusion at a Venezuelan communications organization that uncovered the previously undocumented GoCaracal Go framework.
- GoCaracal comes in lightweight and extended builds, with the lightweight implant offering remote shell and payload execution and the extended build adding browser cookie theft, keylogging, remote desktop, SOCKS5 proxying, file search, and persistence.
- The attackers delivered the malware through Spanish‑language phishing using weaponized SVG files that redirect through URL shorteners to archives and a Delphi loader that deploys GoCaracal and Bandook in a multi‑stage chain.
- If the primary C2 is unreachable the extended GoCaracal issues an eth_getStorageAt call to a public Ethereum JSON‑RPC endpoint to read a replacement C2 address from a smart contract and write it into memory before retrying contact.
- Arctic Wolf released YARA rules and representative IoCs and assessed the activity as linked to Dark Caracal with medium confidence while noting no public proof yet that an infected host used the Ethereum fallback and the full victim count remains unknown.