GoCaracal Malware Uses Ethereum for Backup C2 Servers

A newly identified malware framework known as GoCaracal is using Ethereum infrastructure as a backup method for recovering command-and-control (C2) server information during cyberattacks, according to cybersecurity firm Arctic Wolf. Researchers discovered the Go-based malware during a June 2026 intrusion targeting a communications organization in Venezuela. GoCaracal provides attackers with remote shell access and the ability to download and execute additional malicious payloads. An extended version also includes browser data theft, keylogging, remote desktop control and SOCKS5 proxy…  

Source:: GoCaracal Malware Uses Ethereum for Backup C2 Servers