GoCaracal Malware Taps Ethereum for Backup C2 Access
GoCaracal is a newly identified remote-access and information-stealing malware strain used by a cyber-espionage group to target telecommunications organizations, according to security firm Arctic Wolf. The campaign is notable for incorporating a public blockchain into its command-and-control infrastructure, giving operators a resilient channel that is harder for defenders to disable than a conventional domain or fixed IP address.
Arctic Wolf said GoCaracal uses an Ethereum smart contract as a fallback mechanism for retrieving the latest command-and-control server address. By updating the contract, attackers can redirect infected systems to a new endpoint without modifying or redistributing the malware. The technique complicates disruption efforts because blocking one server, domain or IP address may not sever access if the implant can obtain replacement connection details from the blockchain.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →