Find notable cyber news and cases, enriched with sources, timelines, and signals.

Dark Caracal GoCaracal Latin American phishing campaign

Campaign
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

Dark Caracal-linked operators deployed GoCaracal in a June 2026 intrusion, expanding a regional operation that combined phishing tradecraft, malware deployment, and Latin American targeting. The activity matters because the framework supported remote shell access, payload execution, and additional theft and control functions. Analysts also tied the operation to Bandook use and recurring delivery patterns across related infrastructure. The evidence points to a broader campaign thread rather than a one-off malware sample.

Related Happenings

GoCaracal malware framework deployed during June 2026 Venezuela intrusion

Malware Activity
H score28 First: 27.08.2026 12:33 Last: 27.08.2026 12:33 Sources 1

How related: Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela.

About this happening: The GoCaracal malware framework surfaced in a June 2026 intrusion against an unnamed communications organization in Venezuela, giving operators remote shell access...

Timeline

  1. 27.08.2026 12:33 2 articles · 10h ago

    Dark Caracal GoCaracal Latin American phishing campaign

    Initial Disclosure

    The operation surfaced in a June 2026 intrusion against an unnamed communications organization in Venezuela, where GoCaracal was first observed. Early indicators also showed phishing delivery traits and the later use of Bandook alongside the new malware framework.

    Show sources