GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

August 27, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: Medium
Victim: Communications organizations
Incident: The deployment of GoCaracal malware within a Venezuelan communications organization.
Impact: Unauthorized remote shell access, sensitive browser data theft, and persistent network surveillance.
Attacker: Dark Caracal
Analysis: GoCaracal employs a dual-profile approach, offering both lightweight remote access and extended data exfiltration capabilities. Its most notable feature is the use of Ethereum JSON-RPC endpoints to retrieve backup C2 addresses when primary servers fail. This allows operators to update infrastructure without having to ship new binaries to infected hosts.
Recommendations: Monitor for unusual outbound JSON-RPC requests to public Ethereum endpoints; Enhance email security filters to scrutinize or block SVG attachments; Deploy YARA rules and IoCs to hunt for GoCaracal signatures in system memory
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *