Dark Caracal Unveils a Harder-to-Remove Spyware Stack
Arctic Wolf found Lebanon-linked Dark Caracal using a new GoCaracal malware framework in a targeted intrusion in Venezuela. The group is running two variants: a lightweight first stage for initial access and payload delivery, and a heavier build for intelligence collection and persistent interactive control.
The larger build can use a public Ethereum database to find replacement command-and-control servers if its main server goes offline. In plain terms, the implant is not just a one-shot dropper; it can bring in the next tool and keep a backup path for the operators, which makes cleanup harder than blocking a single server or removing the first lure.
For organizations in Venezuela and elsewhere in Latin America that receive Spanish-language, document-themed phishing, the lasting exposure is a staged espionage chain rather than one file or one domain. If the first stage lands, the follow-on tooling and fallback infrastructure can preserve access after the obvious entry point is gone.