Dark Caracal Deploys GoCaracal Malware in Targeted Venezuela Cyberespionage Attack
Arctic Wolf Labs has uncovered a newly developed Go-based malware framework called GoCaracal, which was used in a targeted intrusion against a communications organization in Venezuela.
Researchers attributed the activity with medium confidence to Dark Caracal, a cyberespionage group associated with Lebanon’s General Directorate of General Security.
The campaign demonstrates how the threat actor continues to evolve its tooling and delivery infrastructure while maintaining phishing techniques previously observed in operations targeting Spanish-speaking victims across Latin America.
Dark Caracal Deploys GoCaracal Malware
According to Arctic Wolf, researchers identified 249 GoCaracal samples, revealing rapid development between January and July 2026.
Earlier Dark Caracal campaigns relied on financial-themed phishing emails, malicious SVG attachments, URL-shortening services, and a Delphi-based loader.
The latest operation retains several of these techniques but introduces GoCaracal alongside an updated version of the Bandook remote-access trojan, indicating a layered malware strategy designed to establish access before deploying more capable surveillance and remote-control components.
The initial infection chain reportedly involved weaponized SVG files containing Base64-encoded shortened URLs. When victims opened the attachments, they were redirected to attacker-controlled infrastructure, including the defanged domain getpdfdigital[.]cloud.
The website delivered a 7-Zip archive containing a lightweight GoCaracal executable. This approach allows attackers to disguise malicious payload delivery behind seemingly legitimate document or file-sharing workflows while leveraging users’ trust in common attachment formats.
GoCaracal currently appears to have two principal build profiles. The lightweight variant functions primarily as an initial-access and payload-delivery implant, collecting information about the compromised system before communicating with the attackers.
Arctic Wolf observed it gathering the username, hostname, operating system, system uptime, active window information, and installed security products.
Communications with the command-and-control infrastructure use a custom protocol protected by AES-GCM encryption, helping conceal commands and data exchanged between infected systems and attacker infrastructure.
Once established, the lightweight implant can download and execute files, retrieve content from specified URLs, provide an interactive command shell, load shellcode, and inject code into other processes.
Researchers determined that this version served as an entry-point tool during the Venezuelan intrusion. After initial access was established, the attackers deployed a Delphi loader containing Bandook together with the more feature-rich GoCaracal variant, suggesting that the framework is being integrated into a broader operational toolkit rather than replacing existing malware.
The extended GoCaracal variant contains 34 command handlers and significantly expands the attacker’s capabilities. These functions support file management, system discovery, process enumeration, keylogging, browser credential theft, targeted file searches, remote desktop functionality, hidden browser sessions, SOCKS5 proxying, and registry modifications associated with persistence.
Such capabilities allow operators to move from basic system reconnaissance toward sustained surveillance, credential collection, remote control, and potential lateral movement.
Researchers also identified internal GoCaracal version identifiers ranging from v1.0.1 through v1.0.6, providing evidence that the malware is actively maintained and evolving. One particularly notable capability is its Ethereum-based fallback mechanism.
If the primary command-and-control server becomes unavailable, GoCaracal can query a public Ethereum JSON-RPC endpoint and obtain an alternative C2 address from a smart contract.
Using blockchain infrastructure as a fallback communication mechanism can make infrastructure takedowns and conventional domain-based blocking more difficult.
The discovery highlights the continuing evolution of Dark Caracal’s operations and the growing importance of monitoring phishing attachments, shortened URLs, suspicious archive downloads, and unusual execution chains.
Security teams should hunt for GoCaracal-related file hashes and infrastructure within controlled threat-intelligence platforms, while monitoring for suspicious PowerShell or command-shell activity, process injection, browser credential access, registry persistence, and unexpected outbound connections.
Organizations operating in Latin America should also strengthen email filtering and SVG attachment inspection, as the campaign demonstrates how familiar social-engineering techniques can be combined with rapidly evolving malware to maintain long-term cyberespionage operations.
No Comment! Be the first one.