news.mlab.sh
Back to the feed
threat-intel

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

Medium
Image: The Hacker News
Summary

Threat actors linked to Dark Caracal have deployed a new Go-based malware framework, GoCaracal, utilizing an Ethereum smart contract to dynamically update its command-and-control (C2) address. This allows operators to change the malware's C2 server without requiring a new binary deployment, adding a layer of sophistication to the attack. Arctic Wolf has released YARA rules and IoCs to aid in detection and hunting efforts.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.