threat-intel
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
Medium
Summary
Threat actors linked to Dark Caracal have deployed a new Go-based malware framework, GoCaracal, utilizing an Ethereum smart contract to dynamically update its command-and-control (C2) address. This allows operators to change the malware's C2 server without requiring a new binary deployment, adding a layer of sophistication to the attack. Arctic Wolf has released YARA rules and IoCs to aid in detection and hunting efforts.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
