🔍 Contexte
En juin 2026, Arctic Wolf Labs a investigué une intrusion ciblée contre une organisation du secteur des communications au Venezuela. L’activité est attribuée avec confiance moyenne au groupe de cyberespionnage Dark Caracal, associé à la Direction Générale de la Sécurité Générale (GDGS) du Liban.
🦠 Nouveau framework : GoCaracal
Les analystes ont identifié un framework modulaire inédit écrit en Go, baptisé GoCaracal, déployé aux côtés d’une variante mise à jour de Bandook. L’analyse de 249 échantillons révèle deux profils opérationnels :
- Profil léger : implant d’accès initial, profilage hôte, shell distant, téléchargement/exécution de payloads, injection de shellcode
- Profil étendu : accès persistant, collecte de renseignements, keylogging, accès bureau via WebRTC, proxy SOCKS5, collecte de cookies navigateur, manipulation de registre, et fallback C2 via Ethereum
⛓️ Mécanisme C2 via Ethereum
Le profil étendu implémente un contrat Solidity nommé BulletproofC2 permettant de récupérer une adresse C2 de remplacement via eth_getStorageAt sur un endpoint JSON-RPC Ethereum public. Ce mécanisme a été testé et opérationnalisé (non dormant), avec des déploiements observés sur le réseau de test Sepolia avant le mainnet. Le wallet de déploiement (0x7D321FE277f8c25aaC14aF1BA3Fc34953242052F) est financé via une infrastructure associée à Binance.
📦 Chaîne de livraison
La chaîne d’infection repose sur :
- Emails de phishing à thème financier/fiscal en espagnol
- Pièces jointes SVG malveillantes avec URL Base64 encodée
- Redirection via services de raccourcissement d’URL
- Téléchargement depuis
getpdfdigital[.]cloud - Archive 7-Zip contenant l’implant léger GoCaracal (
tf-oficina004a9.exe) - Déploiement d’un loader Delphi contenant Bandook + GoCaracal étendu
📈 Évolution du framework (janvier–juillet 2026)
- Phase 1 (janvier) : communications de base, profilage hôte, chiffrement AES-GCM
- Phase 2 (février–avril) : modularisation, support C2 actif, découverte antivirus
- Phase 3 (mai–juin) : capacités post-compromission étendues
- Phase 4 (juin–juillet) : fallback C2 Ethereum opérationnalisé
🌐 Infrastructure et ciblage
- 23 des 24 adresses C2 GoCaracal hébergées sur les réseaux AEZA Group
- C2 Bandook hébergés sur AlexHost (déjà associé à Dark Caracal)
- 7 domaines de livraison identifiés, à thème documentaire en espagnol
- Activité confirmée au Venezuela, avec des artefacts liés au Brésil, Équateur, Chili, Colombie, El Salvador et Uruguay
📋 Type d’article
Il s’agit d’une publication de recherche technique produite par Arctic Wolf Labs, visant à documenter l’évolution des capacités offensives de Dark Caracal, fournir des IOCs exploitables et des règles YARA pour la détection défensive.
🧠 TTPs et IOCs détectés
Acteurs de menace
- Dark Caracal (state-sponsored) — orkl.eu · Malpedia · MITRE ATT&CK
TTP
- T1566.001 — Phishing: Spearphishing Attachment (Initial Access)
- T1566.002 — Phishing: Spearphishing Link (Initial Access)
- T1059.003 — Command and Scripting Interpreter: Windows Command Shell (Execution)
- T1055 — Process Injection (Defense Evasion)
- T1027 — Obfuscated Files or Information (Defense Evasion)
- T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
- T1102 — Web Service (Command and Control)
- T1573.001 — Encrypted Channel: Symmetric Cryptography (Command and Control)
- T1090.001 — Proxy: Internal Proxy (Command and Control)
- T1041 — Exfiltration Over C2 Channel (Exfiltration)
- T1056.001 — Input Capture: Keylogging (Collection)
- T1539 — Steal Web Session Cookie (Credential Access)
- T1552.001 — Unsecured Credentials: Credentials In Files (Credential Access)
- T1547.001 — Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (Persistence)
- T1105 — Ingress Tool Transfer (Command and Control)
- T1082 — System Information Discovery (Discovery)
- T1083 — File and Directory Discovery (Discovery)
- T1057 — Process Discovery (Discovery)
- T1518.001 — Software Discovery: Security Software Discovery (Discovery)
- T1219 — Remote Access Software (Command and Control)
IOC
- IPv4 :
109.120.187.217— AbuseIPDB · VT · ThreatFox - IPv4 :
109.172.95.121— AbuseIPDB · VT · ThreatFox - IPv4 :
138.124.112.213— AbuseIPDB · VT · ThreatFox - IPv4 :
138.124.14.130— AbuseIPDB · VT · ThreatFox - IPv4 :
176.124.220.153— AbuseIPDB · VT · ThreatFox - IPv4 :
185.125.101.181— AbuseIPDB · VT · ThreatFox - Domaines :
getpdfdigital.cloud— VT · URLhaus · ThreatFox - Domaines :
getpdf.digital— VT · URLhaus · ThreatFox - Domaines :
visualizarpdf.online— VT · URLhaus · ThreatFox - Domaines :
contabilidad.icu— VT · URLhaus · ThreatFox - Domaines :
soportedigital.cloud— VT · URLhaus · ThreatFox - Domaines :
documentodigital.cloud— VT · URLhaus · ThreatFox - Domaines :
gestionadocs.me— VT · URLhaus · ThreatFox - SHA256 :
1E499C815146124C4A6D2B48C99068B980AD74E1A2CFD16013F8D75A9425A0CA— VT · MalwareBazaar - SHA256 :
77F7AD29F4A8037EE5F38D3D87FB91CFD97CB8F7FA7883EDF3FCE506DF5200C0— VT · MalwareBazaar - SHA256 :
8C03D072DF2E1BF14B0C00A8AB99834138C8B69F301849BF09CB44394E916015— VT · MalwareBazaar - SHA256 :
0A6DA70548F14834ACB8960689A589B48FF422F8385AE445A281AAB77045FE22— VT · MalwareBazaar - SHA256 :
c9da1b08a39491dfdbede6ff4c1a2d383f57cb29e2d3532aee08d6e0a5c1dda6— VT · MalwareBazaar - Fichiers :
tf-oficina004a9.exe - Fichiers :
TF-OFICINA004A9.exe - Fichiers :
VRJDL_21812.exe - Chemins :
%AppData%\Roaming\d30547514515\91ed375e.exe - Chemins :
%AppData%\Roaming\e1d58f51c58a\5c0416e4.exe
⚠️ À propos de ces IOC — ils sont extraits automatiquement de l’article original le 16 septembre 2026 et n’ont pas fait l’objet d’une vérification externe. Un indicateur peut avoir été réattribué depuis : une IP de C2 peut redevenir un service légitime, un domaine sinkholé peut changer de propriétaire. Aucune garantie d’exactitude ni d’actualité — contrôlez leur validité avant tout usage opérationnel, en particulier avant de les injecter dans une blocklist ou un SIEM.
Malware / Outils
- GoCaracal (framework)
- Bandook (rat)
- AsioGate (backdoor)
🟢 Indice de vérification factuelle : 95/100 (haute)
- ✅ arcticwolf.com — source reconnue (liste interne) (20pts)
- ✅ 21625 chars — texte complet (fulltext extrait) (15pts)
- ✅ 23 IOCs dont des hashes (15pts)
- ✅ 6/9 IOCs confirmés (AbuseIPDB, MalwareBazaar, ThreatFox, URLhaus, VirusTotal) (15pts)
- ✅ 20 TTPs MITRE identifiées (15pts)
- ✅ date extraite du HTML source (10pts)
- ✅ acteur(s) identifié(s) : Dark Caracal (5pts)
- ⬜ pas de CVE à vérifier (0pts)
IOCs confirmés externellement :
109.120.187.217(ip) → VT (4/91 détections)109.172.95.121(ip) → VT (4/91 détections)138.124.112.213(ip) → VT (4/91 détections)getpdfdigital.cloud(domain) → VT (17/91 détections)getpdf.digital(domain) → VT (15/91 détections)
🔗 Source originale : https://arcticwolf.com/resources/blog/dark-caracal-reloaded-new-malware-same-hunting-grounds/