Dark Caracal Adds New Malware to Cyber Espionage Arsenal

Dark Caracal’s Latest Addition: A New Malware Framework for Cyber Espionage

A sophisticated cyber espionage operation has just gotten a significant upgrade. Dark Caracal, a threat group linked to Lebanon’s General Directorate of General Security (GDGS), has added a new malware framework called GoCaracal to its arsenal. This modular malware tool allows the group to steal sensitive data and maintain access to compromised systems with even greater ease.

Researchers at Arctic Wolf discovered GoCaracal when investigating a targeted intrusion in Venezuela, where they found it deployed alongside an updated version of Bandook, a commercially available Windows remote access Trojan. The security company’s analysis revealed that Dark Caracal is using two versions of GoCaracal: a lightweight implant for initial access and downloading additional payloads, and a more substantial build for harvesting intelligence and maintaining interactive control on compromised systems.

What sets GoCaracal apart from its predecessor, AsioGate, is its use of an Ethereum-based blockchain database as a backup source for finding command-and-control servers. This feature allows the threat actors to maintain access to compromised systems even if their primary C2 infrastructure becomes unavailable. In other words, Dark Caracal has created a redundant system that makes it harder for security teams to disrupt their operations.

Dark Caracal’s cyber espionage operation has been active since at least 2012 and has targeted a broad range of organizations and individuals, including military and government personnel, businesses, journalists, activists, lawyers, medical professionals, and educational institutions. The group has used various tactics such as phishing, malicious websites, and Trojanized mobile applications to deliver malware and steal sensitive data.

The discovery of GoCaracal is significant because it shows that Dark Caracal continues to evolve and improve its capabilities. While the threat actors appear to be maintaining their established targeting and delivery tactics in their ongoing Latin American campaign, they are now using a more sophisticated toolset to achieve their goals. Arctic Wolf’s telemetry suggests potential targeting in several countries, including Brazil, Ecuador, Uruguay, El Salvador, Colombia, and Chile.

The practical takeaway from this development is that organizations, particularly those in the targeted regions, should remain vigilant and take proactive measures to protect themselves against cyber espionage attacks. This includes implementing robust security protocols, conducting regular vulnerability assessments, and staying up-to-date with the latest threat intelligence. By doing so, they can reduce their risk of being compromised by sophisticated threat groups like Dark Caracal.


Source: Dark Reading — 2026-08-26