Back to top
  • 공유 Share
  • 인쇄 Print
  • 글자크기 Font size
URL copied.

GoCaracal Malware Uses Ethereum for Backup C2 Servers

GoCaracal Malware Uses Ethereum for Backup C2 Servers. Source: Photo by panumas nikhomkhai

A newly identified malware framework known as GoCaracal is using Ethereum infrastructure as a backup method for recovering command-and-control (C2) server information during cyberattacks, according to cybersecurity firm Arctic Wolf.

Researchers discovered the Go-based malware during a June 2026 intrusion targeting a communications organization in Venezuela. GoCaracal provides attackers with remote shell access and the ability to download and execute additional malicious payloads. An extended version also includes browser data theft, keylogging, remote desktop control and SOCKS5 proxy capabilities.

GoCaracal initially attempts to connect with a configured C2 server through conventional internet infrastructure. If repeated connections fail, the malware can query a public Ethereum JSON-RPC endpoint to obtain an alternative server address.

The malware uses the Ethereum method “eth_getStorageAt” to retrieve information stored in a configured smart contract. The returned data contains a replacement C2 address, which is loaded into GoCaracal's active memory before the malware attempts another standard internet connection.

Arctic Wolf stressed that Ethereum does not host GoCaracal's entire command-and-control system. Instead, the blockchain serves as a resilient way to distribute updated server details. This allows operators to change fallback addresses without deploying a new malware binary, while multiple public RPC providers can access the same smart contract information.

Researchers have not confirmed whether GoCaracal successfully used the Ethereum fallback mechanism during the June attack.

Arctic Wolf assessed with medium confidence that the campaign is linked to the Dark Caracal threat group. The connection is based on similarities involving Bandook malware, Delphi loaders, Spanish-language financial lures, malicious SVG files and URL-shortening services. Bandook was also deployed during the observed intrusion.

To help organizations detect GoCaracal malware, Arctic Wolf released a YARA rule alongside file hashes, domains, IP addresses, host paths and Ethereum smart contract indicators.

Researchers also identified more than 100 malicious SVG files connected to related infrastructure, suggesting phishing was likely used for initial access. However, investigators did not recover the original phishing email or SVG attachment from the compromised organization.

<Copyright ⓒ TokenPost, unauthorized reproduction and redistribution prohibited>

Most Popular

Comment 0

Comment tips

Great article. Requesting a follow-up. Excellent analysis.

0/1000

Comment tips

Great article. Requesting a follow-up. Excellent analysis.
1