Threat Intelligence

Dark Caracal group enhances cyberespionage with new GoCaracal malware

Laptop screen showing malware warning sign with digital circuit background on desk in modern office environment with natural light and creative concept.

The Lebanon-linked Dark Caracal threat group has upgraded its cyberespionage arsenal with a previously unknown malware framework, GoCaracal, which provides broader capabilities for stealing data and maintaining persistent access to compromised systems, according to Dark Reading.

Arctic Wolf researchers discovered GoCaracal during an investigation into a targeted intrusion in Venezuela. The malware framework exists in two versions: a lightweight implant for initial access and a more substantial build for intelligence harvesting and interactive control. Notably, the extended version utilizes an Ethereum blockchain database as a backup for command-and-control servers. Dark Caracal, active since at least 2012 and linked to Lebanon's General Directorate of General Security, has historically targeted a wide range of organizations and individuals, including military, government, journalists, and businesses. Their tactics include phishing, malicious websites, and trojanized mobile applications. The group has also employed custom malware like Pallas and a modified version of the Bandook remote access trojan.

The current campaign appears to maintain established targeting and delivery tactics, using Spanish-language lures and targeting potential victims in several Latin American countries. The GoCaracal framework is under active development, showing increased sophistication and resilience against takedown attempts, posing a significant risk of persistent, undetected footholds in target environments for intelligence gathering.

Source: Dark Reading

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds