GoCaracal is a modular Go-based remote-access framework identified in lightweight and extended profiles. The lightweight profile performs host profiling, establishes encrypted command-and-control communications, provides an interactive remote shell, retrieves and executes payloads, and loads and injects shellcode. The extended profile adds host and file discovery, command execution, browser-cookie and login-data collection, keylogging, targeted file searching, hidden browser interaction, WebRTC-based remote desktop access, SOCKS5 proxying, and persistence-related functionality. Its extended builds can query an Ethereum smart contract for a replacement command-and-control address after repeated failures to contact the primary server, then resume conventional off-chain communications using the retrieved address. GoCaracal was deployed alongside Bandook during a targeted June 2026 intrusion against a Venezuelan communications organization. Delivery was assessed as likely involving phishing using Spanish-language financial or tax-themed lures and malicious SVG content, although the original phishing message was not recovered. Available evidence indicates that GoCaracal augmented, rather than replaced, Bandook.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Threat actors Arctic Wolf links with medium confidence to Dark Caracal used the previously undocumented Go-based GoCaracal malware framework during a June 2026 intrusion against an unnamed communications organization in Venezuela.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
GoCaracal provides operators with remote shell access and payload execution... [and] supports... interactive shell access.
During initialization, it gathers basic host information, including user, hostname, operating-system, uptime...
Host discovery: system profiling, process enumeration, drive discovery, directory listing, and recursive file search.
Network enablement: an in-band SOCKS5 proxy that can tunnel operator traffic through the compromised host.
По повеќекратни неуспешни обиди, тој испраќа барање eth_getStorageAt до јавен Ethereum JSON-RPC endpoint. Одговорот обезбедува заменска адреса складирана во конфигурираниот паметен договор.
Lightweight верзијата поддржува ... преземање и извршување payload-и.
Проширениот профил додава ... далечинска работна површина преку Web Real-Time Communication (WebRTC).
After repeated failures to reach the primary C2, the malware sends an eth_getStorageAt request to a public Ethereum JSON-RPC endpoint and reads a value from the configured contract's storage.
41 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Go-based modular remote-access malware available in lightweight and extended profiles. The lightweight profile performs host profiling, encrypted C2 communications, interactive shell access, payload download/execution, and shellcode loading/injection. The extended profile adds browser cookie and credential-database theft, keylogging, targeted file searching, hidden browser interaction, WebRTC remote desktop control, SOCKS5 proxying, and persistence-related capabilities. If its primary C2 is unavailable, it can obtain a replacement C2 address from data in an Ethereum smart contract via public JSON-RPC endpoints, then resume normal off-chain C2 communications.
Go-based modular malware framework with lightweight and extended profiles. It provides encrypted C2, host profiling, interactive remote shell access, payload retrieval/execution, and shellcode loading/injection. The extended profile adds system/file discovery, browser cookie and login-database theft, keylogging, targeted file search, WebRTC remote desktop control, hidden browser interaction, SOCKS5 proxying, and persistence-related functions. It can query an Ethereum smart contract via public JSON-RPC endpoints to obtain a replacement off-chain C2 address after its primary C2 repeatedly fails.
A modular Go-based framework with lightweight and extended profiles. The lightweight implant profiles hosts, communicates with encrypted C2, provides a remote shell, downloads and executes payloads, and injects shellcode. The extended profile adds file and browser credential collection, keylogging, SOCKS5 proxying, WebRTC/hidden-browser remote interaction, persistence, and an Ethereum smart-contract fallback for obtaining replacement C2 addresses.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.