The Lebanon-linked Dark Caracal threat group has upgraded its cyberespionage arsenal with a previously unknown malware framework that gives the threat actor broader capabilities for stealing data and maintaining persistent access to compromised systems.
Researchers at Arctic Wolf discovered the new malware when investigating a targeted intrusion in Venezuela and are tracking the new framework as GoCaracal.
Dark Caracal’s New Tricks
In a report this week, the security vendor said its analysis of some 250 samples of the malware revealed the threat actor is using two versions of GoCaracal. One of them is a lightweight implant for initial access and downloading additional payloads while the other is a more substantial build for harvesting intelligence and maintaining interactive control on compromised systems. The extended version of GoCaracal uses a public blockchain-based Ethereum database as a backup source for finding command-and-control servers if its main C2 infrastructure becomes unavailable.
“The infrastructure associated with the June 2026 intrusion forms part of a broader cluster of Spanish-language, document-themed domains used to deliver malicious SVG files and downstream payloads,” Arctic Wolf researchers wrote in the report.
Dark Caracal is a long-running cyber-espionage operation that researchers have previously linked to Lebanon’s General Directorate of General Security (GDGS). The group has been active since at least 2012 and has been associated with intelligence gathering operations that have targeted a broad range of organizations and individuals including military and government personnel, businesses, journalists, activists, lawyers, medical professionals and educational institutions.
The group has used a variety of tactics such as phishing, malicious websites and Trojanized mobile applications to deliver malware and to steal documents, communications, credentials, photos and other sensitive data. Dark Caracal’s malware toolkit includes Pallas a custom-developed toolkit for stealing data from Android devices and a custom version of Bandook, a commercially available Windows remote access Trojan that multiple threat actors have been using since 2007.
According to Arctic Wolf, Dark Caracal appears to be maintaining its established targeting and delivery tactics in its ongoing Latin American campaign, using Spanish-language, financial, and document-themed lures to deliver malicious SVG files and subsequent payloads. The security company said its telemetry points to potential targeting in Brazil, Ecuador, Uruguay, El Salvador, Colombia and Chile, although the evidence linking all of the activity to Dark Caracal is not equally strong.
In the June 2026 intrusion that Arctic Wolf investigated at a Venezuelan communications organization, researchers found GoCaracal deployed alongside an updated version of Bandook. Arctic Wolf interpreted that as a sign that Dark Caracal actors are using GoCaracal to complement Bandook’s capabilities rather than to replace it outright, at least for the moment. The threat actors, however, appear to have replaced their earlier AsioGate malware for initial access and post-compromise activities with Dark Caracal, which they are using for file collection, credential theft, keystroke logging, remote shell access and other intelligence-gathering activities.
GoCaracal Under Active Development
GoCaracal is malware the threat actor has been actively developing throughout 2026, Arctic Wolf said. The framework started with relatively basic capabilities for encrypted communications, host profiling and code execution and has evolved into a modular malware tool with reusable components, interactive shells, and features for evading antivirus tools and other security mechanisms. The malware’s support for an Ethereum-based C2 fallback is indication of its growing sophistication and resilience against takedown attempts.
For organizations in the crosshairs of cyber-espionage groups like Dark Caracal, the bigger risk often has to do with the attackers establishing and maintaining a persistent, undetected foothold in the target environment. The objective is not necessarily to steal data immediately, but to quietly gather intelligence about an organization’s people, operations and relationships for potential use in future attacks. Arctic Wolf has provided indicators of compromise and other information that organizations can use to search for or detect signs of malicious activity tied to Dark Caracal activity.

Comments are closed