The June 2026 intrusion affecting a communications organization in Venezuela resulted in deployment of GoCaracal and an updated version of Bandook.
Bandook
Bandook is a Windows remote-access trojan used for espionage-oriented operations, including activity associated with the Lebanon-linked Dark Caracal threat group.
Profile source: Mallory opens in a new tabBandook
Family profile
Bandook is a Windows remote-access trojan used for espionage-oriented operations, including activity associated with the Lebanon-linked Dark Caracal threat group. It has been deployed alongside the GoCaracal framework, including against a Venezuelan communications organization in 2026, indicating continued use within Dark Caracal’s tooling. Bandook supports keylogging, desktop screenshot capture and upload, local file collection and upload over its command-and-control channel, and public IP-address discovery. It can delete files and has used process hollowing by replacing a legitimate browser process with its payload to evade detection. Observed delivery and execution tradecraft includes malicious VBA-enabled lure documents that induce users to enable macros, as well as PowerShell-based loaders. An updated variant randomized command identifiers and obfuscated plugin export names, hindering signature-based detection and analysis.
Capabilities
- Defense Evasion
- Exfiltration
- Keylogging
- Process Injection
- Reconnaissance
Reported operators
Threat actors
4 named in public reportingThe group is known to leverage Bandook-based backdoors in their attacks.
The infection chain features a PDF containing a URL that leads to an encrypted RAR file which installs Bandook malware. The group uses Spanish-languages lures to distribute a known – but infrequently used – remote access trojan (RAT) called Bandook.
The infection chain features a PDF containing a URL that leads to an encrypted RAR file which installs Bandook malware. The group uses Spanish-languages lures to distribute a known – but infrequently used – remote access trojan (RAT) called Bandook.
MITRE ATT&CK
Bandook in ATT&CK
56 distinct techniquesTechniques
56 techniquesReporting
Research mentioning Bandook
Dark Caracal Reloaded: New Malware, Same Hunting Grounds - Malware News - Malware Analysis, News and Indicators
Arctic Wolf Labs investigated a targeted June 2026 intrusion against a communications organization in Venezuela and assessed with medium confidence that the activity was linked to the Dark Caracal threat group. The operation continues the actor's established focus on Latin America, using newly identified malware while pursuing targets in its familiar regional hunting grounds. Researchers linked 249 malware samples to two operational build profiles, indicating a structured and evolving tooling ecosystem. The campaign also used a resilient command-and-control architecture built on Ethereum, complicating disruption and enabling the operators to maintain infrastructure despite conventional takedown efforts.
Dark Caracal Reloaded: New Malware, Same Hunting Grounds - Arctic Wolf
GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
Exposing FakeBat loader: distribution methods and adversary infrastructure
Dark Web Profile: Krybit Ransomware - Malware News - Malware Analysis, News and Indicators
Krybit has emerged as a ransomware-as-a-service (RaaS) operation using double extortion, Tor-hosted leak infrastructure, and a likely Babuk-derived payload targeting Windows, Linux, VMware ESXi, and NAS environments. Reporting indicates the malware deletes shadow copies, appends the .KRYBIT extension to encrypted files, and drops a RECOVER-README.txt ransom note. The group has pursued broad, opportunistic victimization across 43 countries, with Germany, Spain, and Brazil among the most affected geographies and professional services, technology, and manufacturing among the most targeted sectors. Public visibility into Krybit increased after rival RaaS operator 0APT breached Krybit’s affiliate panel in April, exposing plaintext credentials, user roles, negotiation data, Tox IDs, and Bitcoin wallets, with leaked records showing about 20 victims in active negotiations and ransom demands ranging from $40,000 to $100,000. Krybit retaliated by compromising and defacing 0APT’s leak site and publishing its operational data, creating a notable ransomware-on-ransomware conflict. Despite the reputational damage and evidence that no confirmed ransom payment had yet been recorded during the leaked period, Krybit continued naming victims through mid-2026 and showed no public signs of shutting down or rebranding.