Arctic Wolf Uncovers GoCaracal: A Dual-Profile Malware Targeting Latin America
August 27, 2026
GoCaracal exists in two build profiles: a lightweight initial-access implant and a broader extended build with post-compromise capabilities, including credential theft, keylogging, browser data access, WebRTC remote desktop, SOCKS5 proxy, and persistence.
Arctic Wolf researchers identified two versions: a lightweight initial-access implant and a more substantial data-harvesting, persistence-focused build.
GoCaracal is a Go-based malware framework offering remote shell access and payload execution, with the extended profile targeting browser data, keylogging, remote desktop, and proxy features.
An Ethereum-based fallback, via a custom Solidity contract named BulletproofC2, stores a changeable C2 address to switch infrastructure without redeploying the malware.
Observable logs cover email content, URL shorteners, domain infrastructure, C2 traffic, browser navigation, GoCaracal/Bandook activity, shellcode, and registry changes, with Ethereum activity as a notable correlate.
Success requires a user action to open an SVG/archive, followed by payload execution and contact with the primary or Ethereum-backed backup C2; blocking delivery or C2 can halt the campaign.
Phishing is the delivery method, with activity tied to Latin America, including Brazil, Ecuador, Chile, Colombia, El Salvador, and Uruguay (moderate confidence).
Victims may be lured into opening SVGs and archives that resemble financial documents, enabling initial compromise and potential observer activity through hidden browsers.
Defensive guidance advocates restricting SVG/archive delivery, enforcing application control, protecting browser credential stores, monitoring multi-stage chains, and carefully handling Ethereum RPC traffic during investigations.
Attack chain progresses from SVG phishing to a multi-stage payload: host info collection, C2 registration with AES-GCM encryption, and capabilities including shell access, file downloads, and shellcode injection.
Arctic Wolf published a YARA rule and IoCs (hashes, domains, IPs, Ethereum indicators) with full artifact details available to customers.
Dark Caracal has a documented Latin American focus and has evolved from Bandook; current evidence does not confirm GoCaracal as a Bandook replacement.
Summary based on 4 sources
Get a daily email with more Tech stories
Sources

The Hacker News • Aug 27, 2026
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
Security Affairs • Aug 27, 2026
Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback
Dark Reading • Aug 26, 2026
Dark Caracal Adds New Malware to Cyber Espionage Arsenal