threat-intel
Dark Caracal Adds New Malware to Cyber Espionage Arsenal
High
Summary
The Dark Caracal cyber-espionage group, linked to Lebanon, has added a new modular malware framework called GoCaracal to its arsenal. This framework, developed since 2026, is used for data theft, maintaining persistent access, and intelligence gathering, and is being deployed alongside existing malware like Bandook. The group is actively targeting organizations in Latin America, including Brazil, Ecuador, Uruguay, El Salvador, Colombia and Chile, using document-themed lures to deliver malicious content.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
