Security
GoCaracal malware uses Ethereum contract for fallback C2 address
Image: Primary Arctic Wolf reported that a previously undocumented Go-based malware framework, GoCaracal, was used in a June intrusion at an unnamed Venezuelan communications organization.
The lightweight version gives operators remote shell access and payload execution; an extended version adds browser-data theft, keylogging, remote desktop control and SOCKS5 proxying. After failed primary command-and-control attempts, the malware can query an Ethereum smart contract through public RPC endpoints for a replacement C2 address, allowing operators to update that fallback without delivering a new binary.
Arctic Wolf released a YARA rule and indicators.
Sources
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire