Arctic Wolf links new GoCaracal malware and updated Bandook activity to Dark Caracal intrusion in Venezuela

Arctic Wolf says a communications organization in Venezuela was breached in June 2026 in an intrusion it links with medium confidence to the Dark Caracal espionage group. The attackers reportedly used Spanish-language financial lures, malicious SVG attachments, redirect services, document-themed hosting, and a Delphi loader, then deployed a newly documented modular Go-based malware framework called GoCaracal alongside an updated Bandook variant. Arctic Wolf says analysis of 249 samples shows the malware evolved between January and July 2026 and includes an Ethereum smart-contract fallback to recover command-and-control servers.
Why it matters: This matters because it shows a long-running state-linked espionage actor upgrading its malware while keeping phishing methods that can still fool targets. Organizations in Latin America, especially telecom and communications targets, should hunt for SVG-based phishing chains, Delphi loaders, Bandook activity, and unusual outbound connections tied to fallback infrastructure.

Sources

Dark Caracal Reloaded: New Malware, Same Hunting Grounds
Arctic Wolf Labs 2026.08.26 100% relevant
This article appears to establish a distinct new event: a June 2026 Venezuela intrusion attributed to Dark Caracal and the first reporting here on the GoCaracal malware family and its Ethereum-backed command-and-control fallback.
← Back to all stories