GoCaracal: New Go-Based Spyware Hits Venezuelan Telecom

Arctic Wolf ties a June 2026 intrusion at a Venezuelan communications company to Dark Caracal, using a fresh malware framework written in Google's Go language.

ThreatVectr Newsdesk· 4 min read
A developer workstation surrounded by digital threats, symbolizing malware infiltration
Share

Key points

  • Arctic Wolf researchers, with medium confidence, attribute a June 2026 intrusion at a Venezuelan communications company to Dark Caracal, a long-running cyber-espionage group.
  • The attackers used a new, previously undocumented malware framework called GoCaracal, written in Google's Go programming language.
  • GoCaracal gives the operators a remote command line on infected machines and the ability to run more malicious software on demand.
  • An extended version adds browser data theft, keystroke logging, and full remote desktop control, meaning the attackers can watch and drive the computer in real time.
  • The named victim is a communications organisation in Venezuela; the company has not been publicly identified.

A cyber-espionage crew that has been spying on governments, activists and companies for more than a decade appears to have a new tool in its kit.

Security firm Arctic Wolf says operators linked to Dark Caracal broke into an unnamed communications organisation in Venezuela in June 2026 and installed a previously unseen malware framework the researchers are calling GoCaracal. The finding was first reported by The Hacker News.

Arctic Wolf's attribution is at medium confidence, meaning the technical fingerprints line up with Dark Caracal's past work but stop short of a definitive match.

Who is Dark Caracal?

Dark Caracal is a cyber-espionage group first exposed in 2018 by digital rights researchers, who tied its campaigns to targets in more than 20 countries. It is best known for stealing documents, chat logs and call recordings from journalists, lawyers and dissidents, and has been linked in past reporting to work carried out on behalf of a nation state.

The group has shifted tools several times over the years. GoCaracal is the latest.

What does GoCaracal actually do?

GoCaracal is spyware, meaning malicious software designed to sit quietly on a computer and give an outside operator control of it. Arctic Wolf describes two flavours of the framework.

The base version is deliberately minimal. It gives the attackers a remote shell, which is a text-based command line into the infected machine, and lets them push down and run additional payloads later. That keeps the initial footprint small and harder for antivirus tools to spot.

The extended profile is where the surveillance kit widens out. It adds four capabilities:

Capability What it means in plain English
Browser data theft Grabs saved passwords, cookies and browsing history from web browsers
Keylogging Records every keystroke, including messages and login details
Remote desktop control Lets the operator see and drive the screen live, as if sitting at the keyboard
Payload execution Runs further malware chosen by the operator at any time

Written in Go, a language made by Google that produces one self-contained file per target operating system, GoCaracal is straightforward for the attackers to compile for Windows, Linux or macOS. That flexibility matters for a group that goes after mixed environments inside telecoms and government networks.

Why does a telecom in Venezuela matter?

Communications companies are prized targets for espionage crews because they carry other people's traffic. A foothold inside a telecom can expose call records, text messages and the metadata of who spoke to whom, which is exactly the intelligence Dark Caracal has chased in past campaigns.

Arctic Wolf has not named the affected organisation, and there is no public indication of how many customers may have been touched. The intrusion was detected during the firm's incident response work.

What should ordinary people take from this?

GoCaracal is not aimed at consumers, and there is no sign of a mass outbreak. It is a targeted tool for spying on specific people through the companies that serve them.

Still, the practical lesson holds for everyone. If a telecom or messaging provider you use warns you of unusual account activity, take it seriously. Turn on two-factor authentication, which asks for a code from your phone as well as your password, and be cautious about unexpected password reset emails or app install prompts, which are the usual first steps in this kind of attack.

© 2026 Threat Vectr