SECURITY·중요도 8·2026. 08. 27.·The Hacker News

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

── KO ──────────────────

GoCaracal 악성코드는 이더리움 스마트 계약을 사용하여 C2 주소를 가져옵니다.

Arctic Wolf에 의해 Dark Caracal과 연결된 위협 배우들은 미지의 Go 기반 악성코드 프레임워크인 GoCaracal을 사용하여 원격 셸 액세스와 페이로드 실행 기능을 제공합니다. 이 악성코드는 브라우저 데이터 도용, 키로깅, 원격 데스크톱 제어를 포함하는 확장 프로필을 추가하여 보안을 위협합니다.


── EN ──────────────────

GoCaracal malware uses Ethereum smart contracts to retrieve C2 addresses.

Threat actors linked to Dark Caracal have deployed a previously undocumented Go-based malware framework called GoCaracal. This malware allows operators remote shell access and payload execution, while also providing an extended profile for browser data theft, keylogging, and remote desktop control capabilities.

원문 보기 →목록으로