Dark Caracal Unveils a Harder-to-Remove Spyware Stack

Arctic Wolf found Lebanon-linked Dark Caracal using a new GoCaracal malware framework in a targeted intrusion in Venezuela. The group is running two variants: a lightweight first stage for initial access and payload delivery, and a heavier build for intelligence collection and persistent interactive control. The larger build can use a public Ethereum database to find replacement command-and-control servers if its main server goes offline. In plain terms, the implant is not just a one-shot dropper; it can bring in the next tool and keep a backup path for the operators, which makes cleanup harder than blocking a single server or removing the first lure. For organizations in Venezuela and elsewhere in Latin America that receive Spanish-language, document-themed phishing, the lasting exposure is a staged espionage chain rather than one file or one domain. If the first stage lands, the follow-on tooling and fallback infrastructure can preserve access after the obvious entry point is gone.

Part of the PlainSec briefing for 2026-08-27

Editions

Sources