GoCaracal Malware Uses Ethereum Smart Contract for C2 Updates
A new Go‑based malware framework called GoCaracal was used in a June 2026 breach of a communications firm in Venezuela, employing an Ethereum smart contract to obtain a replacement command‑and‑control (C2) address.
The intrusion was linked by Arctic Wolf to the Dark Caracal threat group with medium confidence. GoCaracal provides attackers with a remote shell, allowing them to run commands and upload additional payloads. An extended profile of the malware shows it can steal browser data, record keystrokes, and take control of the desktop.
The most unusual aspect of this campaign is the use of a public Ethereum smart contract to store the C2 address. When the original server becomes unavailable, the malware queries the contract on the blockchain to retrieve a new address, making it harder for defenders to disrupt the communication channel.
The victims were employees of the unnamed Venezuelan organization, but the technique could be adopted by other threat actors targeting any network that runs Go binaries. Because the malware is new, most antivirus products do not yet have signatures for it.
To protect yourself, keep all software, especially Go runtime libraries and related tools, up to date. Use reputable endpoint protection that includes behavior‑based detection. Regularly back up critical files and store them offline. Limit internet access for systems that do not need it, and monitor outbound traffic for unusual connections to blockchain nodes.
ComputerScams.com offers free tools such as the Network Traffic Analyzer and the Malware Hash Checker to help users identify suspicious activity. Running these utilities can reveal unexpected calls to blockchain APIs or unknown processes trying to open a remote shell.
If you suspect infection, disconnect the device from the network, run a full scan with an updated anti‑malware solution, and change passwords for all accounts accessed from the compromised machine.
Stay vigilant and verify any unexpected requests for cryptocurrency addresses or blockchain interactions, as these are common tactics in newer malware campaigns.
Source: Read the original report
Safety tip: Immediately review and block any outbound connections to unknown blockchain nodes using your firewall or network security tool.