Dark Caracal's New Malware GoCaracal: From SVG Phishing to Ethereum Backup C2
1. Basic Information Article Title : Dark Caracal Reloaded: New Malware, Same Hunting Grounds Publisher : Arctic Wolf Labs Publication Date : 2026-08-26 Source : Arctic Wolf Labs Related Sources : Dark Reading , Kaspersky Dark Caracal campaign report Related Malware, Threat Groups, CVEs, Products : GoCaracal, Bandook, AsioGate, Dark Caracal, Microsoft Windows, Ethereum JSON-RPC Severity : High 2.…
The Dark Caracal cybercrime group has released a new malware dubbed GoCaracal, part of their ongoing phishing campaign targeting Spanish-language financial and tax themes. Emails, which have not been recovered, contained malicious SVG attachments. Once opened, the SVGs redirected victims to attacker-controlled sites using Base64-encoded URLs and URL shorteners.
These sites delivered a lightweight GoCaracal executable within a 7-Zip archive. Upon execution, GoCaracal collected host information, registered with a custom encrypted C2 protocol, and provided the user with remote shell access, file downloads, and execution capabilities. An extended 34-feature build, activated if the primary C2 fails, further enabled the malware by stealing browser cookies, login databases, conducting keylogging, and searching for files.
In a novel approach, the malware can also communicate with Ethereum smart contracts via JSON-RPC to obtain alternative C2 addresses. This GoCaracal malware, along with supporting tools Bandook and AsioGate, poses a significant threat to Windows systems, particularly for organizations handling sensitive financial and tax data.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.