Dark Caracal GoCaracal Latin American phishing campaign
Campaign
Summary
Hide ▲
Show ▼
Dark Caracal-linked operators deployed GoCaracal in a June 2026 intrusion, expanding a regional operation that combined phishing tradecraft, malware deployment, and Latin American targeting. The activity matters because the framework supported remote shell access, payload execution, and additional theft and control functions. Analysts also tied the operation to Bandook use and recurring delivery patterns across related infrastructure. The evidence points to a broader campaign thread rather than a one-off malware sample.
Related Happenings
GoCaracal malware framework deployed during June 2026 Venezuela intrusion
Malware Activity
H score28
First: 27.08.2026 12:33
Last: 27.08.2026 12:33
Sources 1
How related:
Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela.
About this happening:
The GoCaracal malware framework surfaced in a June 2026 intrusion against an unnamed communications organization in Venezuela, giving operators remote shell access...
GoCaracal malware framework deployed during June 2026 Venezuela intrusion
Malware ActivityHow related: Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela.
About this happening: The GoCaracal malware framework surfaced in a June 2026 intrusion against an unnamed communications organization in Venezuela, giving operators remote shell access...
Timeline
-
27.08.2026 12:33 2 articles · 10h ago
Dark Caracal GoCaracal Latin American phishing campaign
Initial DisclosureThe operation surfaced in a June 2026 intrusion against an unnamed communications organization in Venezuela, where GoCaracal was first observed. Early indicators also showed phishing delivery traits and the later use of Bandook alongside the new malware framework.
Show sources
- GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address — thehackernews.com — 27.08.2026 12:33
- GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address — thehackernews.com — 27.08.2026 12:33