Key facts
- GoCaracal malware uses Ethereum smart contracts for backup command-and-control (C2) access.
- The malware queries an Ethereum JSON-RPC endpoint for an address stored in a smart contract.
- This mechanism allows operators to update C2 server addresses without distributing a new malware binary.
- The activity is linked with medium confidence to the Dark Caracal threat group.
- Arctic Wolf has released detection indicators for GoCaracal.
A newly identified malware framework, GoCaracal, is leveraging Ethereum's smart contract capabilities to establish backup command-and-control (C2) access during cyberattacks. Cybersecurity firm Arctic Wolf observed this Go-based malware in June 2026 during an intrusion targeting a communications organization in Venezuela.