GoCaracal malware framework deployed during June 2026 Venezuela intrusion
Malware Activity
Summary
Hide ▲
Show ▼
The GoCaracal malware framework surfaced in a June 2026 intrusion against an unnamed communications organization in Venezuela, giving operators remote shell access and payload execution on the infected host. The extended profile adds browser data theft, keylogging, remote desktop control, and SOCKS5 proxying, expanding post-compromise control and collection options. Assessors linked the activity to Dark Caracal with medium confidence and shared a YARA rule plus IoCs for hunting.
Related Happenings
Dark Caracal GoCaracal Latin American phishing campaign
Campaign
H score33
First: 27.08.2026 12:33
Last: 27.08.2026 12:33
Sources 1
How related:
The firm based that assessment on Bandook use, recurring Delphi-loader characteristics, Spanish-language financial lures, malicious SVGs, URL shorteners, document-themed infrastructure, hosting-provider preferences, and Latin American targeting.
About this happening:
Dark Caracal-linked operators deployed GoCaracal in a June 2026 intrusion, expanding a regional operation that combined phishing tradecraft, malware deployment, and ...
Dark Caracal GoCaracal Latin American phishing campaign
CampaignHow related: The firm based that assessment on Bandook use, recurring Delphi-loader characteristics, Spanish-language financial lures, malicious SVGs, URL shorteners, document-themed infrastructure, hosting-provider preferences, and Latin American targeting.
About this happening: Dark Caracal-linked operators deployed GoCaracal in a June 2026 intrusion, expanding a regional operation that combined phishing tradecraft, malware deployment, and ...
Timeline
-
27.08.2026 12:33 2 articles · 10h ago
GoCaracal malware framework deployed during June 2026 Venezuela intrusion
Initial DisclosureDuring the June 2026 intrusion, operators deployed GoCaracal inside the victim environment and used its lightweight profile for shell access and payload execution.
Show sources
- GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address — thehackernews.com — 27.08.2026 12:33
- GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address — thehackernews.com — 27.08.2026 12:33