# GoCaracal malware uses Ethereum contract for fallback C2 address

_Thursday, August 27, 2026 at 5:33 AM EDT · Security · Latest · Tier 2 — Notable_

![GoCaracal malware uses Ethereum contract for fallback C2 address — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEieDE2TgdHU9cQ1MQ7milMPfNWnlskvIWM9VB_9t59o4zxCWPtZY5yyhrJ9Pc558pdVGdapBNcv9SP38IyfrHp0KIgLQeYlAQIPGwopzDvg2WimSzte5wkju-6YypllUrEr8-yto3Bx8mZAhfs7Hf64MTLwyDqAUCPEFlSey89QZx3L-xmHFzVBBwQmRVU/s1700-e365/go.jpg)

Arctic Wolf reported that a previously undocumented Go-based malware framework, GoCaracal, was used in a June intrusion at an unnamed Venezuelan communications organization.

The lightweight version gives operators remote shell access and payload execution; an extended version adds browser-data theft, keylogging, remote desktop control and SOCKS5 proxying. After failed primary command-and-control attempts, the malware can query an Ethereum smart contract through public RPC endpoints for a replacement C2 address, allowing operators to update that fallback without delivering a new binary.

Arctic Wolf released a YARA rule and indicators.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/gocaracal-malware-uses-ethereum-smart.html)

---
Canonical: https://techandbusiness.org/newswire/TmxGbQX1-aDxkYF1OTOKFx
Retrieved: 2026-08-27T12:31:45.403Z
Publisher: Tech & Business (techandbusiness.org)
