Arctic Wolf Labs attributed a targeted June 2026 intrusion at a Venezuelan communications-sector organization, with medium confidence, to the Lebanese-linked espionage group Dark Caracal. The campaign deployed a new modular Go-based framework, GoCaracal, alongside an updated variant of the Bandook remote-access trojan (RAT). GoCaracal’s extended profile supports persistence, intelligence collection, keylogging, browser-cookie theft, WebRTC desktop access, SOCKS5 proxying, and Windows Registry manipulation.
The intrusion began with Spanish-language financial or tax-themed phishing messages carrying malicious SVG attachments. Victims were redirected through URL shorteners to document-themed download domains and 7-Zip archives, which ultimately delivered GoCaracal and a Delphi loader containing Bandook. GoCaracal includes an Ethereum-based command-and-control fallback; Arctic Wolf tracked its development from January through July 2026 and found that 23 of 24 observed GoCaracal C2 addresses were hosted on AEZA Group networks, while Bandook infrastructure was hosted at AlexHost.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
GoCaracal development progressed to an operational Ethereum-based command-and-control fallback using the BulletproofC2 Solidity contract, which obtains replacement C2 information through Ethereum JSON-RPC requests.
A targeted intrusion against a Venezuelan communications-sector organization deployed the previously unidentified GoCaracal Go-based framework and an updated Bandook RAT variant. Arctic Wolf Labs attributed the activity to Dark Caracal with medium confidence.
Dark Caracal's GoCaracal framework development began with basic communications functionality and AES-GCM encryption.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.