Dark Caracal has returned with a new tool that helps attackers stay connected when defenders shut down their control servers.
The cyberespionage group is linked by researchers to a Venezuelan communications organization intrusion, where it deployed an unfamiliar Go-based malware framework called GoCaracal alongside its long-used Bandook backdoor.
The campaign begins with Spanish-language financial and tax lures sent through phishing emails.
Weaponized SVG image files conceal shortened links and redirect recipients to payload hosting sites, a technique seen across other malicious SVG delivery campaigns.
The operators then provide an archive that starts a small implant and opens the door to more capable tools. Analysts at Arctic Wolf identified GoCaracal while investigating the June 2026 breach, and assessed that Dark Caracal was responsible.
Arctic Wolf said in a report shared with Cyber Security News (CSN) that its review of 249 samples uncovered two builds: one for initial access and another for longer surveillance and control.
The finding matters because the group appears to be updating its operations without discarding familiar tactics.
Activity relied on phishing, SVG files, a Delphi loader and Bandook; the new framework adds flexibility and makes infrastructure disruption less decisive. Affected organizations may include targets across Latin America, beyond the confirmed Venezuelan incident.
Dark Caracal Hackers Use Ethereum Blockchain
When GoCaracal cannot reach its main control server, its extended version can ask an Ethereum service for data held in a smart contract. That data can supply a replacement server address, allowing the malware to try again without a new file reaching the victim.
The design resembles other Ethereum-based C2 schemes that turn blockchain records into a backup directory rather than a full control channel.
This is not a case of commands being placed directly on Ethereum. Instead, the chain acts as a dead-drop location for configuration information.
Operators can change the contract’s stored value through a blockchain transaction, and infected devices can recover it through multiple services. That makes one server seizure or domain takedown less likely to cut every victim off.
Researchers found a Solidity contract called BulletproofC2, plus activity that showed its configured value was changed to a public address.
Related deployments appeared first on Ethereum’s Sepolia test network and later on mainnet, while some stored private addresses used in testing. That evidence suggests the fallback moved beyond unused code into an operational resilience feature.
Phishing Chain Expands the Risk
The intrusion still depended on a familiar social engineering route. An SVG attachment sends the recipient’s browser through a shortened link and a redirect before the malware archive is delivered.
In an example of the risk, SVG phishing attacks bypass filters because image files may look harmless even when they contain active web content.
The source report says light GoCaracal focuses on gaining a foothold, profiling the host, communicating with operators and fetching further tools.
The extended version can search files, collect browser data and keystrokes, create a proxy, and provide hidden remote desktop access. It also uses methods intended to remain active after restart.
Bandook was delivered in the same intrusion, showing that the newer framework is adding to, rather than immediately replacing, the group’s existing toolkit.
Defenders should treat unexpected SVG attachments as active content, not ordinary images, and review web, email and endpoint records together when they appear.
Blocking known infrastructure, watching for unusual archives and following the warning signs of remote access can help expose the chain early.
Organizations should also look for repeated failed control-server connections followed by Ethereum RPC requests, which may signal an attempt to obtain a replacement destination.
Arctic Wolf also found related artifacts linked to Brazil, Ecuador, Chile, Colombia, El Salvador and Uruguay, though it said the broader regional scope remains under investigation.
The case is a reminder that taking down a server no longer necessarily ends an intrusion. When attackers separate delivery sites, malware control systems and blockchain-based recovery paths, defenders need to disrupt every stage while monitoring for the next connection attempt.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | 1E499C815146124C4A6D2B48C99068B980AD74E1A2CFD16013F8D75A9425A0C |
GoCaracal lightweight variant, TF-OFICINA004A9.exe |
| SHA-256 | 77F7AD29F4A8037EE5F38D3D87FB91CFD97CB8F7FA7883EDF3FCE506DF5200C0 |
GoCaracal lightweight variant, TF-OFICINA004A9.exe |
| SHA-256 | 8C03D072DF2E1BF14B0C00A8AB99834138C8B69F301849BF09CB44394E916015 |
GoCaracal extended variant, VRJDL_21812.exe |
| SHA-256 | 0A6DA70548F14834ACB8960689A589B48FF422F8385AE445A281AAB77045FE22 |
Delphi loader, 7676230602QQ.exe |
| SHA-256 | a2cdf2fe741de4b13ad2298b387a6c32da4a94da180ae75bf8547386aee7376b |
Decrypted Bandook payload |
| Domain | getpdfdigital[.]cloud |
Delivery infrastructure |
| Domain | getpdf[.]digital |
Delivery infrastructure |
| Domain | visualizarpdf[.]online |
Delivery infrastructure |
| Domain | contabilidad[.]icu |
Delivery infrastructure |
| Domain | soportedigital[.]cloud |
Delivery infrastructure |
| Domain | documentodigital[.]cloud |
Delivery infrastructure |
| Domain | gestionadocs[.]me |
Delivery infrastructure and C2 panel |
| IP address | 109[.]120[.]187[.]217 |
GoCaracal C2 infrastructure |
| IP address | 109[.]172[.]95[.]121 |
GoCaracal C2 infrastructure |
| IP address | 138[.]124[.]112[.]213 |
GoCaracal C2 infrastructure |
| IP address | 138[.]124[.]14[.]130 |
GoCaracal C2 infrastructure |
| IP address | 176[.]124[.]220[.]153 |
GoCaracal C2 infrastructure |
| IP address | 185[.]125[.]101[.]181 |
GoCaracal C2 infrastructure |
| IP address | 185[.]96[.]80[.]110 |
GoCaracal C2 infrastructure |
| IP address | 185[.]96[.]80[.]54 |
GoCaracal C2 infrastructure |
| IP address | 193[.]233[.]245[.]52 |
GoCaracal C2 infrastructure |
| IP address | 62[.]60[.]237[.]22 |
GoCaracal C2 infrastructure |
| IP address | 77[.]110[.]104[.]98 |
GoCaracal C2 infrastructure |
| IP address | 77[.]110[.]105[.]244 |
GoCaracal C2 infrastructure |
| IP address | 77[.]110[.]105[.]56 |
GoCaracal C2 infrastructure |
| IP address | 77[.]110[.]105[.]59 |
GoCaracal C2 infrastructure |
| IP address | 77[.]110[.]98[.]66 |
GoCaracal C2 infrastructure |
| IP address | 80[.]71[.]224[.]30 |
GoCaracal C2 infrastructure |
| IP address | 82[.]117[.]87[.]138 |
GoCaracal C2 infrastructure |
| IP address | 82[.]117[.]87[.]192 |
GoCaracal C2 infrastructure |
| IP address | 85[.]192[.]30[.]211 |
GoCaracal C2 infrastructure |
| IP address | 79[.]137[.]192[.]38 |
GoCaracal C2 infrastructure |
| IP address | 193[.]233[.]245[.]0 |
GoCaracal C2 infrastructure |
| IP address | 193[.]233[.]245[.]45 |
GoCaracal C2 infrastructure |
| IP address | 46[.]226[.]162[.]68 |
GoCaracal C2 infrastructure |
| IP address | 45[.]152[.]198[.]108 |
GoCaracal C2 infrastructure |
| IP address | 91[.]208[.]197[.]80 |
Bandook C2 infrastructure |
| IP address | 91[.]208[.]184[.]45 |
Bandook C2 infrastructure |
| IP address | 91[.]208[.]206[.]88 |
Bandook C2 infrastructure |
| IP address | 91[.]208[.]184[.]130 |
Bandook C2 infrastructure |
| IP address | 176[.]123[.]1[.]174 |
Bandook C2 infrastructure |
| User-Agent | Mozilla/5.0 (Windows NT 10.0; Win64; x64) |
Observed user-agent string |
| Ethereum contract | 0x03D605f13A74Bfb6149078122FcF62BD6d8799d8 |
Configured BulletproofC2 fallback contract, deployed May 20, 2026 |
| Ethereum contract | 0x04aB453494381E60171BE04Ea6BE6E7C44EafAfd |
Identical BulletproofC2 deployment linked to the same wallet |
| Ethereum contract | 0xD7635f31620772882a6712472a6278c53247Bc44 |
Identical BulletproofC2 deployment linked to the same wallet |
| Ethereum contract | 0xf165F26300BF65DFaC78BC9557326bDbB3C6d33C |
Identical BulletproofC2 deployment linked to the same wallet |
| Ethereum wallet | 0x7D321FE277f8c25aaC14aF1BA3Fc34953242052F |
Deployment and management wallet for fallback contracts |
| File path | %AppData%\Roaming\d30547514515\91ed375e.exe |
Host-based artifact |
| File path | %AppData%\Roaming\e1d58f51c58a\5c0416e4.exe |
Host-based artifact |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.