Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback
2026-08-28T02:51:37Z•15b1ea68b76024f8f1526ad9c6aa927a6c3985796c47aa9ab9ef9f8aa3ad2b51
CVE-2026-60004APTBandookCISAChina-linked threat actorsDark CaracalEthereumFBI seizure vulnerability managementGoCaracalICSPLCQScanQTRouterSCADATeamPCPVenezuelacloud compromisecommand-and-controlcredential theftcritical infrastructureespionagemalwareopen-source securityred teamsoftware supply chainwater utilities
What happened
Security news roundup covering Dark Caracal’s GoCaracal malware and Ethereum-based command-and-control fallback targeting Venezuela; a TeamPCP open-source supply-chain operation that allegedly stole more than 500,000 credentials; CISA warnings about internet-exposed PLCs and critical-infrastructure compromise; China-linked hacking platforms seized by the FBI; and CISA’s addition of CVE-2026-60004 to the KEV catalog. The feed also includes AI-enabled influence operations, identity-verification data breaches, and strengthened WhatsApp account protections.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 15b1ea68b76024f8f1526ad9c6aa927a6c3985796c47aa9ab9ef9f8aa3ad2b51
- Enrichment time
- 2026-08-28T02:51:37Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.