Dark Caracal Deploys Poco RAT in Latest Cyber Espionage Campaign Targeting Spanish-Speaking Latin America

Listen to this Post

In 2024, a cyber espionage campaign attributed to the notorious hacking group Dark Caracal began targeting Spanish-speaking enterprises across Latin America with a powerful remote access Trojan (RAT) named Poco RAT. This malware is packed with espionage capabilities that allow attackers to fully control compromised systems, exfiltrate sensitive data, and manipulate system processes. The campaign primarily targets companies in Venezuela, Chile, Colombia, Ecuador, and the Dominican Republic, with the threat actor leveraging phishing emails with invoice-themed lures to deploy the malicious payload. Positive Technologies, a Russian cybersecurity firm, uncovered this latest set of attacks and linked them to Dark Caracal based on tradecraft overlaps.

the Attack

Dark Caracal, an advanced persistent threat (APT) group that has been active since at least 2012, has recently been linked to a sophisticated malware campaign targeting Spanish-speaking users in Latin America. The malware, known as Poco RAT, is capable of capturing screenshots, executing commands, uploading files, and manipulating system processes. Researchers have identified its use in phishing campaigns that rely on invoice-related attachments to deliver the RAT.

The infection process begins with victims opening files that redirect them to a legitimate file-sharing service such as Google Drive or Dropbox. The files, disguised with a .rev extension, contain a Delphi-based dropper that launches Poco RAT. Once executed, the malware communicates with a remote server and grants attackers full control over the compromised system.

This marks another chapter in Dark Caracal’s ongoing cyber espionage activities, which have previously been tied to campaigns involving other malware families like CrossRAT and Bandook. The group’s targets primarily include enterprises across several sectors like banking, healthcare, and manufacturing, with a focus on extracting sensitive data.

What Undercode Says:

The latest Dark Caracal operation highlights a significant trend in modern cyber espionage tactics. The use of Poco RAT, with its full suite of espionage features, signals a deliberate and advanced attack strategy targeting key sectors in Spanish-speaking Latin American countries. The group’s persistent focus on these regions, particularly countries like Venezuela and Colombia, suggests a strong geopolitical or economic motive behind their operations. By utilizing phishing emails disguised as invoices, the attackers cleverly exploit a social engineering tactic that increases the likelihood of successful infections.

What makes Poco RAT particularly dangerous is its stealth and persistence. The malware does not initially establish a persistence mechanism, but once the attackers gain a foothold, they can issue commands to ensure ongoing access to the victim’s system. This flexibility allows Dark Caracal to use Poco RAT as a springboard for more sophisticated, long-term cyber espionage campaigns.

The use of .rev files, which are typically used for reconstructing corrupted archives, is a particularly clever evasion tactic. This repurposing of legitimate file extensions makes it harder for traditional security solutions to detect the malware. The fact that the malware is hosted on trusted cloud platforms like Google Drive and Dropbox also shows how threat actors are increasingly leveraging legitimate services to bypass security measures.

Moreover, the focus on sectors such as banking, manufacturing, and healthcare is no coincidence. These industries hold critical information, whether financial, intellectual property, or medical data, all of which are highly valuable for espionage purposes. The ability to monitor and steal this information undetected can have profound implications, not just for the targeted companies, but for national security and economic stability.

Dark Caracal’s long-standing operations, dating back over a decade, show that this group is highly adept at adapting its methods and tools to remain effective in an ever-evolving cyber landscape. While previous campaigns have relied on malware like CrossRAT and Bandook, the of Poco RAT demonstrates the group’s continuous innovation in their toolkit, further complicating efforts to track and defend against their attacks.

These attacks also shed light on the broader threat landscape. As cybercriminals become more sophisticated and their methods more diversified, it becomes evident that organizations must prioritize cybersecurity measures that can detect and mitigate these types of threats. Multi-layered defense strategies, including advanced phishing detection and the ability to identify unusual network traffic or interactions with legitimate cloud services, are crucial to defending against campaigns like this.

In conclusion, Dark Caracal’s latest operations with Poco RAT underline the need for businesses to remain vigilant and proactive in their cybersecurity strategies. The group’s focus on Spanish-speaking Latin American countries is part of a broader trend of increasing cyber threats targeting emerging markets and regions with geopolitical significance.

Fact Checker Results:

  1. The attribution of Dark Caracal to the Poco RAT campaign is supported by tradecraft overlaps identified by Positive Technologies.
  2. Poco RAT is a sophisticated espionage tool with capabilities that include file uploads, screenshot capturing, and system manipulation.
  3. The use of legitimate file-sharing platforms and cloud services for malware distribution is a known tactic used to evade detection and increase the success rate of cyberattacks.

References:

Reported By: https://thehackernews.com/2025/03/dark-caracal-uses-poco-rat-to-target.html
Extra Source Hub:
https://stackoverflow.com
Wikipedia: https://www.wikipedia.org
Undercode AI

Image Source:

OpenAI: https://craiyon.com
Undercode AI DI v2Featured Image