Dark Caracal Deploys GoCaracal Malware Using SVG Phishing and Ethereum Backup C2
Arctic Wolf Labs published research on August 26, 2026, detailing a new campaign by the threat group Dark Caracal, which distributes a Go-based malware called GoCaracal through malicious SVG files disguised as Spanish-language financial and tax documents. Victims are lured via phishing emails into opening SVGs that redirect them through URL shorteners to attacker-controlled sites, where a lightweight GoCaracal executable is delivered inside a 7-Zip archive. Once executed, the malware collects host data, establishes encrypted C2 communication, and deploys an extended build alongside the Delphi-loaded Bandook trojan, enabling browser credential theft, keylogging, SOCKS5 proxying, and WebRTC remote desktop access. Notably, if the primary command-and-control server becomes unreachable, the malware retrieves a backup C2 address stored in an Ethereum smart contract via JSON-RPC calls, making takedown efforts significantly harder. Defenders are advised to block SVG and archive attachments at mail gateways, restrict unauthorized executables, and filter outbound Ethereum JSON-RPC traffic to counter this threat.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in