Find notable cyber news and cases, enriched with sources, timelines, and signals.

GoCaracal malware framework deployed during June 2026 Venezuela intrusion

Malware Activity
First reported
Last updated
Happening score
H score 28
1 unique sources, 1 articles

Summary

Hide ▲

The GoCaracal malware framework surfaced in a June 2026 intrusion against an unnamed communications organization in Venezuela, giving operators remote shell access and payload execution on the infected host. The extended profile adds browser data theft, keylogging, remote desktop control, and SOCKS5 proxying, expanding post-compromise control and collection options. Assessors linked the activity to Dark Caracal with medium confidence and shared a YARA rule plus IoCs for hunting.

Related Happenings

Dark Caracal GoCaracal Latin American phishing campaign

Campaign
H score33 First: 27.08.2026 12:33 Last: 27.08.2026 12:33 Sources 1

How related: The firm based that assessment on Bandook use, recurring Delphi-loader characteristics, Spanish-language financial lures, malicious SVGs, URL shorteners, document-themed infrastructure, hosting-provider preferences, and Latin American targeting.

About this happening: Dark Caracal-linked operators deployed GoCaracal in a June 2026 intrusion, expanding a regional operation that combined phishing tradecraft, malware deployment, and ...

Timeline

  1. 27.08.2026 12:33 2 articles · 10h ago

    GoCaracal malware framework deployed during June 2026 Venezuela intrusion

    Initial Disclosure

    During the June 2026 intrusion, operators deployed GoCaracal inside the victim environment and used its lightweight profile for shell access and payload execution.

    Show sources