Skip to main content
Back to Newswire
Security

GoCaracal malware uses Ethereum contract for fallback C2 address

GoCaracal malware uses Ethereum contract for fallback C2 address Image: Primary
Arctic Wolf reported that a previously undocumented Go-based malware framework, GoCaracal, was used in a June intrusion at an unnamed Venezuelan communications organization. The lightweight version gives operators remote shell access and payload execution; an extended version adds browser-data theft, keylogging, remote desktop control and SOCKS5 proxying. After failed primary command-and-control attempts, the malware can query an Ethereum smart contract through public RPC endpoints for a replacement C2 address, allowing operators to update that fallback without delivering a new binary. Arctic Wolf released a YARA rule and indicators.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire