Arctic Wolf Labs investigated a targeted June 2026 intrusion against a communications organization in Venezuela and assessed with medium confidence that the activity was linked to the Dark Caracal threat group. The operation continues the actor's established focus on Latin America, using newly identified malware while pursuing targets in its familiar regional hunting grounds.
Researchers linked 249 malware samples to two operational build profiles, indicating a structured and evolving tooling ecosystem. The campaign also used a resilient command-and-control architecture built on Ethereum, complicating disruption and enabling the operators to maintain infrastructure despite conventional takedown efforts.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
During June and July, GoCaracal development added an Ethereum smart-contract fallback that could provide a replacement C2 address after repeated primary-C2 failures. Transaction history showed the configured BulletproofC2 contract's stored C2 value had been changed to a public IP address, indicating the mechanism was operationalized.
Arctic Wolf Labs investigated a targeted intrusion against a communications organization in Venezuela and assessed with medium confidence that Dark Caracal was responsible. Victims were directed through a malicious SVG and shortened-URL chain to a payload-hosting site that delivered a lightweight GoCaracal implant; the intrusion later deployed an updated Bandook payload and an extended GoCaracal build.
The observed BulletproofC2 Ethereum fallback contract, 0x03D605f13A74Bfb6149078122FcF62BD6d8799d8, was deployed using wallet 0x7D321FE277f8c25aaC14aF1BA3Fc34953242052F. The contract served as a dead-drop location for replacement GoCaracal C2 configuration data.
GoCaracal development began with core encrypted command-and-control communications and code-execution capabilities.
Arctic Wolf published a YARA rule for GoCaracal's lightweight profile and representative indicators including SHA-256 hashes, domains, IP addresses, Ethereum contracts and wallets, and host paths. The report stated that the complete indicator set was available to Arctic Wolf customers.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 47 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
9 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcecyberaccord.com
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourcemkd-cirt.mk
Open sourcethehackernews.com
Open sourcemalware.news
Open sourcearcticwolf.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.