Ethereum News: GoCaracal Turns to ETH Smart Contract for Backup C2 Access
Highlights
- GoCaracal was found during a June 2026 intrusion at a communications organization in Venezuela.
- The malware can query Ethereum for a replacement C2 address when its primary server becomes unreachable.
- Arctic Wolf links GoCaracal to Dark Caracal with medium confidence based on technical and campaign evidence.
- Arctic Wolf released a YARA rule and IoCs covering hashes, domains, IPs, wallets and Ethereum contracts.
A newly documented malware framework called GoCaracal is using Ethereum infrastructure to support command-and-control recovery during cyberattacks. Arctic Wolf observed the Go-based malware during a June 2026 intrusion involving a communications organization in Venezuela.
The framework gives operators remote shell access and allows them to retrieve and execute additional payloads. Its extended version also supports browser data theft, keylogging, remote desktop control, and SOCKS5 proxy functions.
GoCaracal Uses Ethereum for Backup C2 Access
GoCaracal first attempts to communicate with a configured command-and-control server through a normal off-chain connection. When repeated attempts fail, the malware can query a public Ethereum JSON-RPC endpoint for another address.
The request uses “eth_getStorageAt” to read data stored within a configured Ethereum smart contract. That response contains a replacement C2 address, which GoCaracal places into its active memory configuration.
The malware then returns to conventional internet communication and tries reaching the newly supplied command server. Arctic Wolf said the process does not place the complete C2 channel on Ethereum.
“This mechanism does not place the malware’s full command-and-control channel on Ethereum,” Arctic Wolf said. The blockchain instead acts as a method for distributing updated server details.
Smart Contract Lets Operators Change Server Addresses
The Ethereum setup gives operators a way to change the fallback address without distributing another GoCaracal binary. Multiple public RPC providers can also read the same smart contract data.
That design reduces reliance on one specific RPC service and gives the malware several possible routes to retrieve updated information. However, Arctic Wolf did not confirm successful fallback reconnection during the June incident.
The company said its public evidence does not show a compromised host using Ethereum and then reconnecting successfully. The confirmed victim count outside the reported Venezuelan organization also remains unknown.
Arctic Wolf Links Activity to Dark Caracal
Arctic Wolf assessed with medium confidence that the activity is connected with the Dark Caracal threat group. “We assess with medium confidence that this activity is linked to Dark Caracal,” the company said.
Its assessment draws from several technical and operational patterns seen in earlier campaigns. These include Bandook malware, Delphi loaders, Spanish-language financial lures, malicious SVG files and URL shorteners.
Bandook was also deployed during the intrusion and operated alongside the lighter GoCaracal profile. Arctic Wolf said available evidence does not show GoCaracal replacing Bandook within the attacker’s toolset.
Defenders Receive YARA Rule and Ethereum Indicators
Arctic Wolf published detection material that organizations can use when searching for GoCaracal activity. The released data includes a YARA rule covering the lightweight version of the malware.
Arctic Wolf also released hashes, domains, IP addresses, host paths, and Ethereum contract indicators. The company said the public indicators are representative rather than a complete set.
Consequently, Arctic Wolf suspects phishing, citing more than 100 related SVG files linked to the same malicious infrastructure. Despite all of this, investigators did not recover the original phishing email or malicious SVG attachment from the victim.
For more protection, Web3 enterprises can deploy blockchain transaction monitoring tools to detect and block suspicious smart contract interactions in real time.
Instant Currency Exchange at BestChange with Ease
- Compare Rates Across 1000+ Exchanges
- Access 250+ Cryptocurrencies & Pairs
- Save Time with Real-Time Price Tracking
- Trusted & Verified Exchange Listings


















