Arctic Wolf Uncovers GoCaracal: A Dual-Profile Malware Targeting Latin America

August 27, 2026
Arctic Wolf Uncovers GoCaracal: A Dual-Profile Malware Targeting Latin America
  • GoCaracal exists in two build profiles: a lightweight initial-access implant and a broader extended build with post-compromise capabilities, including credential theft, keylogging, browser data access, WebRTC remote desktop, SOCKS5 proxy, and persistence.

  • Arctic Wolf researchers identified two versions: a lightweight initial-access implant and a more substantial data-harvesting, persistence-focused build.

  • GoCaracal is a Go-based malware framework offering remote shell access and payload execution, with the extended profile targeting browser data, keylogging, remote desktop, and proxy features.

  • An Ethereum-based fallback, via a custom Solidity contract named BulletproofC2, stores a changeable C2 address to switch infrastructure without redeploying the malware.

  • Observable logs cover email content, URL shorteners, domain infrastructure, C2 traffic, browser navigation, GoCaracal/Bandook activity, shellcode, and registry changes, with Ethereum activity as a notable correlate.

  • Success requires a user action to open an SVG/archive, followed by payload execution and contact with the primary or Ethereum-backed backup C2; blocking delivery or C2 can halt the campaign.

  • Phishing is the delivery method, with activity tied to Latin America, including Brazil, Ecuador, Chile, Colombia, El Salvador, and Uruguay (moderate confidence).

  • Victims may be lured into opening SVGs and archives that resemble financial documents, enabling initial compromise and potential observer activity through hidden browsers.

  • Defensive guidance advocates restricting SVG/archive delivery, enforcing application control, protecting browser credential stores, monitoring multi-stage chains, and carefully handling Ethereum RPC traffic during investigations.

  • Attack chain progresses from SVG phishing to a multi-stage payload: host info collection, C2 registration with AES-GCM encryption, and capabilities including shell access, file downloads, and shellcode injection.

  • Arctic Wolf published a YARA rule and IoCs (hashes, domains, IPs, Ethereum indicators) with full artifact details available to customers.

  • Dark Caracal has a documented Latin American focus and has evolved from Bandook; current evidence does not confirm GoCaracal as a Bandook replacement.

Summary based on 4 sources


Get a daily email with more Tech stories

More Stories