Actor Profile

Dark Caracal (G0070) is a threat actor with a documented history of operations in Latin America since at least 2018. Arctic Wolf attributes the June 2026 GoCaracal intrusion to Dark Caracal with medium confidence based on multiple behavioral and technical overlaps: use of Bandook malware, recurring Delphi-loader characteristics, Spanish-language financial lures, malicious SVG files, URL shorteners, document-themed infrastructure, specific hosting-provider preferences, and consistent targeting of Latin American entities. The actor has previously deployed FinFisher, CrossRAT, and Bandook malware families. Dark Caracal's motivation appears focused on espionage and data collection targeting communications and government sectors across the region, with related artifacts linked to Brazil, Ecuador, Chile, Colombia, El Salvador, and Uruguay.

TTPs (Tactics, Techniques, Procedures)

Dark Caracal employed multiple MITRE ATT&CK techniques during the GoCaracal campaign. Initial access likely occurred via phishing (T1566.003) using malicious SVG attachments with financial and tax-themed lures. The GoCaracal malware framework demonstrates obfuscation (T1027.013, T1027.002), command execution via Windows Command Shell (T1059.003), and web protocols for C2 communication (T1071.001). The extended profile includes system and file discovery (T1083), data from local system collection (T1005), screen capture (T1113), and persistence mechanisms (T1547.001). The malware uses compiled HTML files (T1218.001) and requires user execution (T1204.002). A novel technique involves using Ethereum smart contracts via eth_getStorageAt JSON-RPC requests to fetch replacement C2 addresses after primary server failures, providing resilient fallback infrastructure without placing the full C2 channel on-chain.

Targets & Patterns

The confirmed June 2026 intrusion targeted an unnamed communications organization in Venezuela, consistent with Dark Caracal's established pattern of Latin American operations. Arctic Wolf assesses with moderate confidence that broader regional activity extends to Brazil, Ecuador, Chile, Colombia, El Salvador, and Uruguay based on related artifacts and infrastructure, though these are not confirmed victim countries. The targeting of communications infrastructure suggests intelligence collection objectives, with phishing lures using Spanish-language financial and tax themes to achieve initial compromise. Over 100 related SVG files communicating with the same malicious hosting site indicate a broader campaign scope, though the public report does not provide a confirmed count of compromised organizations beyond the single Venezuelan entity.

Historical Context

Dark Caracal was first publicly disclosed in 2018 (covered by The Hacker News). The actor demonstrated continuity through retooled Bandook malware operations in 2020 and subsequent Bandook attacks targeting Venezuela in 2021. The June 2026 GoCaracal intrusion represents an evolution in the actor's toolkit, introducing a previously undocumented Go-based framework while maintaining parallel use of Bandook. Arctic Wolf notes that current evidence does not establish GoCaracal as a replacement for Bandook; instead, both were deployed simultaneously during the investigated intrusion. The consistent use of Delphi loaders, malicious SVGs, Spanish-language lures, and Latin American targeting demonstrates operational continuity spanning at least eight years, with GoCaracal representing a technical advancement rather than a complete operational shift.

Defensive Recommendations

  • Hunt for GoCaracal using Arctic Wolf's published YARA rule targeting the lightweight profile; monitor for Go-compiled binaries with remote shell, payload execution, and encrypted C2 capabilities
  • Detect phishing delivery via malicious SVG attachments (T1566.003) by blocking or sandboxing SVG files from external sources and monitoring for financial/tax-themed lures in Spanish
  • Monitor for eth_getStorageAt JSON-RPC requests to public Ethereum endpoints as anomalous C2 fallback behavior; baseline legitimate blockchain API usage and alert on unexpected queries from non-financial processes
  • Detect browser credential theft (T1005, T1113) by monitoring access to browser cookie stores, login databases (e.g., Chrome Login Data, Firefox logins.json), and enabling tamper protection on credential vaults
  • Implement detection for Bandook malware and Delphi-based loaders given parallel deployment; correlate GoCaracal IoCs with known Dark Caracal infrastructure including document-themed domains and preferred hosting providers

---

# Geopolitical Context

Geopolitical Context

The June 2026 intrusion at a Venezuelan communications organization, attributed with medium confidence to Dark Caracal, represents a continuation of sustained cyber operations targeting Latin American telecommunications infrastructure. Dark Caracal has maintained a documented operational presence in the region since at least 2018, with confirmed activity in Venezuela dating to 2021. The deployment of GoCaracal—a previously undocumented Go-based framework—alongside the established Bandook malware suggests iterative toolset development rather than wholesale operational retooling. The targeting of communications infrastructure in Venezuela is consistent with intelligence collection priorities in a country experiencing prolonged political instability and international isolation. The use of Ethereum smart contracts as a C2 fallback mechanism reflects broader adversary adaptation to network defense capabilities, enabling operational resilience without requiring malware redeployment. Arctic Wolf's assessment identifies infrastructure and artifacts linked to Brazil, Ecuador, Chile, Colombia, El Salvador, and Uruguay, indicating potential regional campaign scope beyond the confirmed Venezuelan intrusion.

State Actor Alignment

Dark Caracal is widely assessed to be linked to Lebanese state interests, specifically the Lebanese General Directorate of General Security (GDGS). The group's sustained focus on Latin America—spanning Venezuela, Brazil, Ecuador, Chile, Colombia, El Salvador, and Uruguay—suggests intelligence collection requirements that extend beyond Lebanon's immediate regional concerns. This geographic focus may indicate tasking related to diaspora monitoring, economic intelligence, or support to regional partners. Dark Caracal has not been subject to formal attribution or sanctions by Western governments, though the group's activities have been publicly documented by multiple security vendors since 2018. The medium-confidence attribution by Arctic Wolf is based on tactical overlaps including Bandook malware use, Delphi-loader characteristics, Spanish-language lures, and targeting patterns consistent with previous Dark Caracal operations. The deployment of novel tooling alongside legacy capabilities suggests continued operational investment and access to development resources.

Business Impacty pro region

The intrusion carries direct implications for telecommunications security across Latin America, a region where communications infrastructure remains a persistent espionage target. Venezuela's telecommunications sector operates under significant state influence and international sanctions pressure, making it a strategically valuable collection target for multiple state and non-state actors. The broader artifact distribution across six additional Latin American countries suggests either active intrusion attempts or preparatory reconnaissance activity spanning the region. For European and North American partners with commercial or diplomatic presence in affected countries, the campaign underscores persistent risks to communications confidentiality in environments where telecommunications providers may lack resources for advanced threat detection. The use of public Ethereum infrastructure for C2 fallback demonstrates how adversaries leverage decentralized technologies to complicate network-based detection and takedown efforts—a technique with implications for defenders globally. The campaign's focus on Spanish-language financial and tax-themed lures indicates targeting of organizations and individuals involved in economic activity, potentially including multinational corporations operating in the region.

Forecast

If Dark Caracal maintains operational tempo consistent with historical patterns, additional intrusions targeting communications and government sectors across Latin America are likely in the coming months. The parallel deployment of GoCaracal and Bandook suggests the group is evaluating new capabilities while retaining proven tools, indicating that both malware families may appear in future operations. If network defenders successfully disrupt primary C2 infrastructure, the Ethereum-based fallback mechanism may see operational use, providing observable indicators for threat hunting. Organizations in Brazil, Ecuador, Chile, Colombia, El Salvador, and Uruguay with infrastructure or artifact links should anticipate potential targeting, particularly in telecommunications, government, and financial sectors. If Western governments increase focus on Lebanon-linked cyber operations amid broader Middle East tensions, Dark Caracal may face increased scrutiny, though the group's Latin American focus may insulate it from immediate policy responses. Defenders should prioritize detection of phishing vectors using SVG attachments and financial-themed lures, as these remain the assessed initial access method.