Dark Caracal Phishes Tax Lures With SVG Files

Security Affairs · High sophistication
Last updated August 27, 2026

Researchers linked a June 2026 intrusion at a communications organization in Venezuela to the Dark Caracal espionage group. The attackers used phishing emails with financial/tax-themed lures and weaponized SVG attachments that redirected victims through URL shorteners to an attacker site hosting malware.

Key findings

  • June 2026 intrusion at a communications organization in Venezuela was assessed (medium confidence) as linked to Dark Caracal.
  • Delivery used phishing emails with financial/tax lures and weaponized SVG attachments, which redirected through URL shorteners to attacker-controlled infrastructure.
  • Opening the SVG led to a shortened URL, then a redirector, then an attacker site (getpdfdigital[.]cloud) that delivered a 7-Zip archive with a Go-based implant.
  • Malware chain included a lightweight GoCaracal implant that later pulled additional payloads including an updated Bandook backdoor and a more capable GoCaracal build.
  • The extended GoCaracal build included an Ethereum smart-contract fallback to obtain replacement C2 addresses if primary C2 failed.

Who’s being targeted

  • Commonly targeted roles: Finance, Accounting/Tax, Executive assistants, All employees (phishing awareness).
  • Affected industries: Telecommunications, Government, Journalism/Media, Businesses, Activists/Non-profits.
  • Attack channels: email, website.
  • Impersonated: Unspecified sender posing as a finance/tax-related contact.

Awareness takeaways

  • Treat unexpected financial/tax emails, especially with unusual attachments like SVG, as suspicious and verify the request through a trusted channel.
  • Be wary of attachments that push you to click a shortened link or redirect to download a file; this is a common way attackers hide their true destination.
  • If a “document” download arrives as a compressed archive (e.g., 7-Zip), stop and report it, this is a strong sign of malware delivery.

Red flags to watch for

  • Unexpected SVG attachment for a financial/tax document
  • Attachment triggers a browser redirect via a URL shortener/redirector
  • Download arrives as a compressed archive (7-Zip) instead of a normal PDF/document
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: “Subject: Tax/financial document (see attached)”… but the attachment is an SVG image file. This is Dark Caracal’s play: that SVG isn’t a document at all. When you open it, your browser quietly jumps to a shortened link, then to getpdfdigital.cloud, which offers a 7‑Zip download instead of a normal PDF. That 7‑Zip isn’t “just documents”, it hides a GoCaracal implant that can pull more payloads, including an updated Bandook backdoor, and even uses an Ethereum smart contract to swap in new command servers if the old ones die. Your move: if a “tax document” comes as an SVG or makes you click through a short link to download a 7‑Zip, stop and report it to security immediately.

Similar attacks

Korea Flags Job-Offer Phish + Watering Holes

Korea Flags Job-Offer Phish + Watering Holes

South Korean agencies warned that a state-backed hacking group is actively targeting citizens and businesses using job-themed phishing emails and “watering hole” attacks on legitimate websites. The phishing lures include fake job applicants sending resume links and impersonated recruiters sending…

July 31, 2026
Fake Notepad++ Plugin Used in Ukraine Phish

Fake Notepad++ Plugin Used in Ukraine Phish

CERT-UA reports a real phishing campaign linked to Russia-aligned actor UAC-0099 targeting Ukrainian organizations. Victims receive an email with an image attachment that leads (via a link shortener) to a file-sharing download, where a disguised script installs a trojanized Notepad++ plugin and…

July 24, 2026
Phish Lures Steal Bank Logins via Telegram

Phish Lures Steal Bank Logins via Telegram

The report describes confirmed phishing activity targeting the financial sector, where victims were tricked into fake login pages via emails, links, or HTML attachments. The credentials entered were then exfiltrated to attackers through Telegram using APIs. The same report also highlights ongoing…

August 24, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Check Point says North Korea’s Lazarus Group targeted defense and aerospace professionals using convincing fake job offers that led victims to download trojanized PDF software. The campaign used a Windows zero-day (now patched as CVE-2026-68820) to gain full control and hide from security tools,…

August 13, 2026
Lazarus Lures Staff With Fake Jobs to Drop Malware

Lazarus Lures Staff With Fake Jobs to Drop Malware

Researchers tied North Korea’s Lazarus Group to a real-world campaign that approaches professionals with convincing fake recruiter outreach and job offers. Victims are tricked into opening a malicious PDF or installing a fake PDF viewer from lookalike websites, which then installs backdoors and can…

August 12, 2026