GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

Summary

A new Go-based malware framework, GoCaracal, has been identified and linked to threat actors associated with Dark Caracal. This malware provides operators with remote shell access, payload execution, browser data theft, and keylogging capabilities.

IFF Assessment

FOE

The discovery of a new, feature-rich malware framework signifies a new tool available to adversaries, posing a direct threat to defenders.

Defender Context

Defenders should be aware of this new GoCaracal malware, particularly its capabilities for remote access and data exfiltration. Monitoring for unusual network traffic and system behavior that aligns with these functionalities will be crucial for detection and mitigation.

Read Full Story →