GoCaracal Malware Leverages Ethereum Smart Contracts for C2 Recovery
A new Go-based malware framework identified as GoCaracal has been observed utilizing Ethereum smart contracts to maintain command-and-control access during cyberattacks. Arctic Wolf researchers discovered the malware during a June 2026 incident targeting a communications firm in Venezuela. The framework enables remote shell access and the execution of secondary payloads, with advanced versions incorporating additional functionality.