A newly identified malware framework known as GoCaracal is using Ethereum infrastructure as a backup method for recovering command-and-control (C2) server information during cyberattacks, according to cybersecurity firm Arctic Wolf. Researchers discovered the Go-based malware during a June 2026 intrusion targeting a communications organization in Venezuela.