Skip to content
Threat Feed
medium threat

Dark Caracal Evolving Infrastructure and Targeting

Arctic Wolf Labs identified 249 Dark Caracal malware samples utilizing an Ethereum-based C2 architecture to target the communications sector in Latin America.

Arctic Wolf Labs has detailed the evolution of the threat actor Dark Caracal, documenting a campaign that demonstrates both technical maturation and persistent regional targeting. Analysis of 249 unique malware samples has uncovered two distinct operational build profiles utilized by the actor. A significant development in their tradecraft is the implementation of a resilient, Ethereum-based command-and-control (C2) architecture. This infrastructure change allows the group to maintain persistent communications with compromised hosts while complicating traditional network-based blocking.

In June 2026, researchers observed this updated tooling in a targeted intrusion against a communications entity in Venezuela. This confirms that the group continues to focus on high-value targets within the Latin American communications sector. The ability to pivot between infrastructure components while maintaining consistent build profiles highlights the group's capacity for sustained, long-term operations. Defenders should prioritize visibility into non-standard C2 traffic and anomalous process execution chains originating from communications infrastructure.

Impact

The activity represents a direct threat to the communications sector in Latin America. Successful exploitation results in persistent unauthorized access to internal network environments, enabling potential data exfiltration and long-term espionage against strategic infrastructure. As of June 2026, the activity has been specifically identified impacting organizations in Venezuela.

Recommendation

  • Implement network monitoring to identify anomalous traffic patterns potentially associated with decentralized or Ethereum-based C2 communications.
  • Establish baseline behavior for network-facing processes and monitor for unexpected socket creation or external connections.
  • Review and harden endpoint security configurations to block unauthorized or unverified binary execution within the communications sector.
  • Monitor for suspicious artifacts consistent with the identified build profiles; ensure all endpoint detection and response (EDR) solutions are configured to log process-creation metadata.

Immediate actions

Review internal network traffic for non-standard or anomalous C2 communication patterns.

SOC 48h

Threat Hunt

Process creation logs for suspicious binaries lacking standard enterprise signatures.

T1204 medium medium confidence hunt now

Data: Sysmon Event ID 1

Enrichment needed

  • Malware sample IOCs (CTI) Indicators are required for proactive blocking and detection.

Mitigations

Harden communications infrastructure and monitor for egress traffic to unknown endpoints.

short_term IT Operations

Persistent C2 TTPs

Gaps

  • Lack of specific file hashes or C2 domain/IP indicators.