The Lebanon-linked Dark Caracal threat group has upgraded its cyberespionage arsenal with a previously unknown malware framework, GoCaracal, which provides broader capabilities for stealing data and maintaining persistent access to compromised systems, according to Dark Reading.Arctic Wolf researchers discovered GoCaracal during an investigation into a targeted intrusion in Venezuela. The malware framework exists in two versions: a lightweight implant for initial access and a more substantial build for intelligence harvesting and interactive control. Notably, the extended version utilizes an Ethereum blockchain database as a backup for command-and-control servers. Dark Caracal, active since at least 2012 and linked to Lebanon's General Directorate of General Security, has historically targeted a wide range of organizations and individuals, including military, government, journalists, and businesses. Their tactics include phishing, malicious websites, and trojanized mobile applications. The group has also employed custom malware like Pallas and a modified version of the Bandook remote access trojan.The current campaign appears to maintain established targeting and delivery tactics, using Spanish-language lures and targeting potential victims in several Latin American countries. The GoCaracal framework is under active development, showing increased sophistication and resilience against takedown attempts, posing a significant risk of persistent, undetected footholds in target environments for intelligence gathering.Source: Dark Reading
Threat Intelligence
Dark Caracal group enhances cyberespionage with new GoCaracal malware
(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
