Dark Caracal has returned with a new tool that helps attackers stay connected when defenders shut down their control servers.

The cyberespionage group is linked by researchers to a Venezuelan communications organization intrusion, where it deployed an unfamiliar Go-based malware framework called GoCaracal alongside its long-used Bandook backdoor.

The campaign begins with Spanish-language financial and tax lures sent through phishing emails.

Weaponized SVG image files conceal shortened links and redirect recipients to payload hosting sites, a technique seen across other malicious SVG delivery campaigns.

The operators then provide an archive that starts a small implant and opens the door to more capable tools. Analysts at Arctic Wolf identified GoCaracal while investigating the June 2026 breach, and assessed that Dark Caracal was responsible.

Arctic Wolf said in a report shared with Cyber Security News (CSN) that its review of 249 samples uncovered two builds: one for initial access and another for longer surveillance and control.

The finding matters because the group appears to be updating its operations without discarding familiar tactics.

Activity relied on phishing, SVG files, a Delphi loader and Bandook; the new framework adds flexibility and makes infrastructure disruption less decisive. Affected organizations may include targets across Latin America, beyond the confirmed Venezuelan incident.

Dark Caracal Hackers Use Ethereum Blockchain

When GoCaracal cannot reach its main control server, its extended version can ask an Ethereum service for data held in a smart contract. That data can supply a replacement server address, allowing the malware to try again without a new file reaching the victim.

The design resembles other Ethereum-based C2 schemes that turn blockchain records into a backup directory rather than a full control channel.

This is not a case of commands being placed directly on Ethereum. Instead, the chain acts as a dead-drop location for configuration information.

Progression of GoCaracal delivery via phishing (Source – Arctic Wolf)

Operators can change the contract’s stored value through a blockchain transaction, and infected devices can recover it through multiple services. That makes one server seizure or domain takedown less likely to cut every victim off.

Researchers found a Solidity contract called BulletproofC2, plus activity that showed its configured value was changed to a public address.

Related deployments appeared first on Ethereum’s Sepolia test network and later on mainnet, while some stored private addresses used in testing. That evidence suggests the fallback moved beyond unused code into an operational resilience feature.

Phishing Chain Expands the Risk

The intrusion still depended on a familiar social engineering route. An SVG attachment sends the recipient’s browser through a shortened link and a redirect before the malware archive is delivered.

In an example of the risk, SVG phishing attacks bypass filters because image files may look harmless even when they contain active web content.

The source report says light GoCaracal focuses on gaining a foothold, profiling the host, communicating with operators and fetching further tools.

The extended version can search files, collect browser data and keystrokes, create a proxy, and provide hidden remote desktop access. It also uses methods intended to remain active after restart.

Bandook was delivered in the same intrusion, showing that the newer framework is adding to, rather than immediately replacing, the group’s existing toolkit.

Defenders should treat unexpected SVG attachments as active content, not ordinary images, and review web, email and endpoint records together when they appear.

Blocking known infrastructure, watching for unusual archives and following the warning signs of remote access can help expose the chain early.

Organizations should also look for repeated failed control-server connections followed by Ethereum RPC requests, which may signal an attempt to obtain a replacement destination.

Arctic Wolf also found related artifacts linked to Brazil, Ecuador, Chile, Colombia, El Salvador and Uruguay, though it said the broader regional scope remains under investigation.

The case is a reminder that taking down a server no longer necessarily ends an intrusion. When attackers separate delivery sites, malware control systems and blockchain-based recovery paths, defenders need to disrupt every stage while monitoring for the next connection attempt.

Indicators of compromise (IoCs):-

Type Indicator Description
SHA-256 1E499C815146124C4A6D2B48C99068B980AD74E1A2CFD16013F8D75A9425A0C GoCaracal lightweight variant, TF-OFICINA004A9.exe
SHA-256 77F7AD29F4A8037EE5F38D3D87FB91CFD97CB8F7FA7883EDF3FCE506DF5200C0 GoCaracal lightweight variant, TF-OFICINA004A9.exe
SHA-256 8C03D072DF2E1BF14B0C00A8AB99834138C8B69F301849BF09CB44394E916015 GoCaracal extended variant, VRJDL_21812.exe
SHA-256 0A6DA70548F14834ACB8960689A589B48FF422F8385AE445A281AAB77045FE22 Delphi loader, 7676230602QQ.exe
SHA-256 a2cdf2fe741de4b13ad2298b387a6c32da4a94da180ae75bf8547386aee7376b Decrypted Bandook payload
Domain getpdfdigital[.]cloud Delivery infrastructure
Domain getpdf[.]digital Delivery infrastructure
Domain visualizarpdf[.]online Delivery infrastructure
Domain contabilidad[.]icu Delivery infrastructure
Domain soportedigital[.]cloud Delivery infrastructure
Domain documentodigital[.]cloud Delivery infrastructure
Domain gestionadocs[.]me Delivery infrastructure and C2 panel
IP address 109[.]120[.]187[.]217 GoCaracal C2 infrastructure
IP address 109[.]172[.]95[.]121 GoCaracal C2 infrastructure
IP address 138[.]124[.]112[.]213 GoCaracal C2 infrastructure
IP address 138[.]124[.]14[.]130 GoCaracal C2 infrastructure
IP address 176[.]124[.]220[.]153 GoCaracal C2 infrastructure
IP address 185[.]125[.]101[.]181 GoCaracal C2 infrastructure
IP address 185[.]96[.]80[.]110 GoCaracal C2 infrastructure
IP address 185[.]96[.]80[.]54 GoCaracal C2 infrastructure
IP address 193[.]233[.]245[.]52 GoCaracal C2 infrastructure
IP address 62[.]60[.]237[.]22 GoCaracal C2 infrastructure
IP address 77[.]110[.]104[.]98 GoCaracal C2 infrastructure
IP address 77[.]110[.]105[.]244 GoCaracal C2 infrastructure
IP address 77[.]110[.]105[.]56 GoCaracal C2 infrastructure
IP address 77[.]110[.]105[.]59 GoCaracal C2 infrastructure
IP address 77[.]110[.]98[.]66 GoCaracal C2 infrastructure
IP address 80[.]71[.]224[.]30 GoCaracal C2 infrastructure
IP address 82[.]117[.]87[.]138 GoCaracal C2 infrastructure
IP address 82[.]117[.]87[.]192 GoCaracal C2 infrastructure
IP address 85[.]192[.]30[.]211 GoCaracal C2 infrastructure
IP address 79[.]137[.]192[.]38 GoCaracal C2 infrastructure
IP address 193[.]233[.]245[.]0 GoCaracal C2 infrastructure
IP address 193[.]233[.]245[.]45 GoCaracal C2 infrastructure
IP address 46[.]226[.]162[.]68 GoCaracal C2 infrastructure
IP address 45[.]152[.]198[.]108 GoCaracal C2 infrastructure
IP address 91[.]208[.]197[.]80 Bandook C2 infrastructure
IP address 91[.]208[.]184[.]45 Bandook C2 infrastructure
IP address 91[.]208[.]206[.]88 Bandook C2 infrastructure
IP address 91[.]208[.]184[.]130 Bandook C2 infrastructure
IP address 176[.]123[.]1[.]174 Bandook C2 infrastructure
User-Agent Mozilla/5.0 (Windows NT 10.0; Win64; x64) Observed user-agent string
Ethereum contract 0x03D605f13A74Bfb6149078122FcF62BD6d8799d8 Configured BulletproofC2 fallback contract, deployed May 20, 2026
Ethereum contract 0x04aB453494381E60171BE04Ea6BE6E7C44EafAfd Identical BulletproofC2 deployment linked to the same wallet
Ethereum contract 0xD7635f31620772882a6712472a6278c53247Bc44 Identical BulletproofC2 deployment linked to the same wallet
Ethereum contract 0xf165F26300BF65DFaC78BC9557326bDbB3C6d33C Identical BulletproofC2 deployment linked to the same wallet
Ethereum wallet 0x7D321FE277f8c25aaC14aF1BA3Fc34953242052F Deployment and management wallet for fallback contracts
File path %AppData%\Roaming\d30547514515\91ed375e.exe Host-based artifact
File path %AppData%\Roaming\e1d58f51c58a\5c0416e4.exe Host-based artifact

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.