Ethereum News: GoCaracal Turns to ETH Smart Contract for Backup C2 Access

Coingapestaff
Updated
Coingapestaff

Coingapestaff

Journalist
CoinGape comprises an experienced team of native content writers and editors working round the clock to cover news globally and present news as a fact rather than an opinion. CoinGape writers and reporters contributed to this article.
Read full bio
Why Trust CoinGape
CoinGape has covered the cryptocurrency industry since 2017, aiming to provide informative insights to our readers. Our journal analysts bring years of experience in market analysis and blockchain technology to ensure factual accuracy and balanced reporting. By following our Editorial Policy, our writers verify every source, fact-check each story, rely on reputable sources, and attribute quotes and media correctly. We also follow a rigorous Review Methodology when evaluating exchanges and tools. From emerging blockchain projects and coin launches to industry events and technical developments, we cover all facets of the digital asset space with unwavering commitment to timely, relevant information.
AN IMAGE OF ETHEREUM
Sponsored This page may contain affiliate links. If you sign up through these links, we may earn a commission at no additional cost to you. This does not influence our editorial reviews or rankings.

Highlights

  • GoCaracal was found during a June 2026 intrusion at a communications organization in Venezuela.
  • The malware can query Ethereum for a replacement C2 address when its primary server becomes unreachable.
  • Arctic Wolf links GoCaracal to Dark Caracal with medium confidence based on technical and campaign evidence.
  • Arctic Wolf released a YARA rule and IoCs covering hashes, domains, IPs, wallets and Ethereum contracts.

A newly documented malware framework called GoCaracal is using Ethereum infrastructure to support command-and-control recovery during cyberattacks. Arctic Wolf observed the Go-based malware during a June 2026 intrusion involving a communications organization in Venezuela.

The framework gives operators remote shell access and allows them to retrieve and execute additional payloads. Its extended version also supports browser data theft, keylogging, remote desktop control, and SOCKS5 proxy functions.

GoCaracal Uses Ethereum for Backup C2 Access

GoCaracal first attempts to communicate with a configured command-and-control server through a normal off-chain connection. When repeated attempts fail, the malware can query a public Ethereum JSON-RPC endpoint for another address.

The request uses “eth_getStorageAt” to read data stored within a configured Ethereum smart contract. That response contains a replacement C2 address, which GoCaracal places into its active memory configuration.

The malware then returns to conventional internet communication and tries reaching the newly supplied command server. Arctic Wolf said the process does not place the complete C2 channel on Ethereum.

“This mechanism does not place the malware’s full command-and-control channel on Ethereum,” Arctic Wolf said. The blockchain instead acts as a method for distributing updated server details.

Smart Contract Lets Operators Change Server Addresses

The Ethereum setup gives operators a way to change the fallback address without distributing another GoCaracal binary. Multiple public RPC providers can also read the same smart contract data.

That design reduces reliance on one specific RPC service and gives the malware several possible routes to retrieve updated information. However, Arctic Wolf did not confirm successful fallback reconnection during the June incident.

The company said its public evidence does not show a compromised host using Ethereum and then reconnecting successfully. The confirmed victim count outside the reported Venezuelan organization also remains unknown.

Arctic Wolf Links Activity to Dark Caracal

Arctic Wolf assessed with medium confidence that the activity is connected with the Dark Caracal threat group. “We assess with medium confidence that this activity is linked to Dark Caracal,” the company said.

Its assessment draws from several technical and operational patterns seen in earlier campaigns. These include Bandook malware, Delphi loaders, Spanish-language financial lures, malicious SVG files and URL shorteners.

Bandook was also deployed during the intrusion and operated alongside the lighter GoCaracal profile. Arctic Wolf said available evidence does not show GoCaracal replacing Bandook within the attacker’s toolset.

Defenders Receive YARA Rule and Ethereum Indicators

Arctic Wolf published detection material that organizations can use when searching for GoCaracal activity. The released data includes a YARA rule covering the lightweight version of the malware.

Arctic Wolf also released hashes, domains, IP addresses, host paths, and Ethereum contract indicators. The company said the public indicators are representative rather than a complete set.

Consequently, Arctic Wolf suspects phishing, citing more than 100 related SVG files linked to the same malicious infrastructure. Despite all of this, investigators did not recover the original phishing email or malicious SVG attachment from the victim.

For more protection, Web3 enterprises can deploy blockchain transaction monitoring tools to detect and block suspicious smart contract interactions in real time.

Investment disclaimer: The content reflects the author’s personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses.
Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over our editorial content.
AD
BestChange

Instant Currency Exchange at BestChange with Ease

  • Compare Rates Across 1000+ Exchanges
  • Access 250+ Cryptocurrencies & Pairs
  • Save Time with Real-Time Price Tracking
  • Trusted & Verified Exchange Listings
MemeToro

Why Trust CoinGape

CoinGape has covered the cryptocurrency industry since 2017, aiming to provide informative insights Read more… to our readers. Our journal analysts bring years of experience in market analysis and blockchain technology to ensure factual accuracy and balanced reporting. By following our Editorial Policy, our writers verify every source, fact-check each story, rely on reputable sources, and attribute quotes and media correctly. We also follow a rigorous Review Methodology when evaluating exchanges and tools. From emerging blockchain projects and coin launches to industry events and technical developments, we cover all facets of the digital asset space with unwavering commitment to timely, relevant information.

Newsletter
Your crypto brief.
Delivered every day.
  • Insights that move markets
  • 100,000 active subscribers
By signing-up you agree to our Terms and Conditions and Privacy Policy.
About Author
About Author
CoinGape comprises an experienced team of native content writers and editors working round the clock to cover news globally and present news as a fact rather than an opinion. CoinGape writers and reporters contributed to this article.