GoCaracal is a modular Go-based remote-access malware framework associated with medium confidence with the Lebanon-linked Dark Caracal cyberespionage group. It was identified during a June 2026 intrusion targeting a communications organization in Venezuela, where it operated alongside the Bandook backdoor. GoCaracal comprises a lightweight initial-access profile and a more capable extended profile. The lightweight profile fingerprints compromised hosts, establishes encrypted command-and-control communications, provides interactive shell access, retrieves and executes further payloads, and can load and inject shellcode. The extended profile supports system and file discovery, targeted file searching, browser login-database and cookie collection, keylogging, hidden browser sessions, SOCKS5 proxying, WebRTC-based remote desktop access, command execution, and persistence. After repeated failures to contact its primary command-and-control infrastructure, extended builds can query the BulletproofC2 Ethereum smart contract for a replacement off-chain command-and-control address. This blockchain mechanism acts as a mutable dead-drop configuration service rather than a full on-chain command channel. GoCaracal was delivered in a campaign using Spanish-language financial and tax-themed phishing lures, weaponized SVG attachments, shortened links, and malicious archives, with a Delphi loader used to deploy additional components. Available evidence indicates that GoCaracal augments, rather than replaces, Dark Caracal's established Bandook tooling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GoCaracal appears in two variants: a lightweight implant that establishes initial access and drops additional payloads, and an extended build for sustained intelligence collection and interactive control.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
“The campaign begins with Spanish-language financial and tax lures sent through phishing emails.”
« Version étendue : ... keylogging » ; « T1056.001 — Input Capture: Keylogging ».
“The extended build adds ... browser credential and cookie theft.”
La liste TTP cite « T1071 — Application Layer Protocol (Command and Control) » ; GoCaracal communique avec les opérateurs et contacte des services RPC Ethereum.
“Infected devices can recover it through multiple services” and defenders are advised to identify “Ethereum RPC requests.”
« Version étendue : ... création de proxy » ; « T1090 — Proxy (Command and Control) ».
« Les machines infectées récupèrent cette valeur via plusieurs services RPC Ethereum » ; « T1102 — Web Service (Command and Control) ».
“When GoCaracal cannot reach its main control server, its extended version can ask an Ethereum service for data held in a smart contract.”
« Livraison d’une archive contenant un implant léger ouvrant l’accès à des outils plus avancés » et « Version légère : ... téléchargement d’outils supplémentaires ».
48 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously undocumented Go-based modular malware framework used in an intrusion against a Venezuelan communications organization. Its lightweight variant establishes access and deploys payloads, while the extended variant enables intelligence collection and interactive control, including an Ethereum smart-contract C2 fallback.
Framework malveillant écrit en Go, déployé par Dark Caracal. Sa variante légère effectue le profilage de l’hôte, communique avec les opérateurs et télécharge des outils additionnels. La variante étendue collecte des fichiers et données de navigateur, enregistre les frappes, établit un proxy, fournit un accès bureau distant furtif et persiste après redémarrage. En cas d’indisponibilité du C2 principal, elle récupère une adresse C2 de repli depuis un contrat intelligent Ethereum.
A Go-based modular espionage framework with lightweight and extended builds. The lightweight variant establishes an initial foothold, profiles hosts, communicates with operators, and retrieves additional tools. The extended variant can search files, steal browser data and keystrokes, create a proxy, provide concealed remote-desktop access, and maintain persistence. If its primary C2 is unavailable, it retrieves a replacement C2 address from a BulletproofC2 Ethereum smart contract.
A Go-based modular malware framework used by Dark Caracal. It has lightweight initial-access and extended surveillance/control builds. Its extended variant uses Ethereum smart-contract data as a dead-drop fallback to obtain replacement C2 server addresses when its primary C2 is unreachable, improving resilience against infrastructure takedowns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.