Mark RadarMARK RADAR
About
EN
Sign in
Event File CRYPTO Ethereum

GoCaracal Malware Taps Ethereum for Backup C2 Access

1 reports · First detected 2026-08-31 · Last active 2026-08-31

GoCaracal is a newly identified remote-access and information-stealing malware strain used by a cyber-espionage group to target telecommunications organizations, according to security firm Arctic Wolf. The campaign is notable for incorporating a public blockchain into its command-and-control infrastructure, giving operators a resilient channel that is harder for defenders to disable than a conventional domain or fixed IP address.

Arctic Wolf said GoCaracal uses an Ethereum smart contract as a fallback mechanism for retrieving the latest command-and-control server address. By updating the contract, attackers can redirect infected systems to a new endpoint without modifying or redistributing the malware. The technique complicates disruption efforts because blocking one server, domain or IP address may not sever access if the implant can obtain replacement connection details from the blockchain.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)