Skip to content

CastleLoader

CastleLoader is a Windows malware loader and malware-as-a-service delivery framework active since at least early 2025.

Profile source: Mallory opens in a new tab

CastleLoader

Family profile

CastleLoader is a Windows malware loader and malware-as-a-service delivery framework active since at least early 2025. It is commonly described as a multi-stage shellcode loader used as the initial infection component in campaigns that subsequently deploy a wide range of secondary payloads, including remote access trojans, information stealers, remote management tools, and cryptocurrency-focused theft tooling. Reported follow-on malware includes CastleRAT, CastleStealer, NetSupport RAT, SectopRAT, NeedleStealer-related components, and other commodity stealers and loaders.

CastleLoader is strongly associated with the threat cluster TAG-150 and has been characterized as an entry point to the broader CastleRAT platform. It has also been observed in multiple campaign clusters tracked under names including Urutyka, Garrigin, Noidret, and BackgroundFix. The malware has been linked to both C-based and Python-based variants, and some reporting describes it as a flexible MaaS framework designed for in-memory task execution and modular payload deployment.

Delivery is most often tied to ClickFix-style social engineering and fake verification or CAPTCHA pages that trick victims into copying and executing malicious commands. Additional observed lures include fake software installers, fake update pages, job-platform impersonation, and malicious ads or landing pages. Infection chains frequently abuse native Windows utilities and portable interpreter runtimes, including Bring-Your-Own-Interpreter approaches using Python or IronPython, to stage later components while reducing obvious on-disk artifacts.

Technically, CastleLoader has been observed retrieving encrypted tasking from command-and-control infrastructure, decrypting configuration in memory, and launching additional payloads through numerous execution methods. Reported capabilities include shellcode-based in-memory loading, process injection into legitimate processes, anti-virtualization and anti-analysis checks, host profiling, screenshot capture, and delivery of further malware. Some campaigns used digitally signed installers, Node.js-based injectors, or IronPython-based chains to execute CastleLoader stages. Its role across campaigns is primarily to establish execution and deliver secondary tooling rather than to serve as the final objective itself.

CastleLoader has been used against Windows users across broad criminal intrusion activity rather than a single vertical, with observed impacts ranging from credential and data theft to remote access and cryptocurrency theft. Its recurring use in socially engineered paste-and-run chains, fileless or low-artifact staging, and modular payload delivery has made it a notable loader in 2026 threat reporting.

Capabilities

  • Defense Evasion
  • Initial Access
  • Post Exploitation
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 9, 2026
Last activity
Sep 9, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • RU1

Leading providers

  • New Hosting Technologies LLC1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

4 named in public reporting
TAG-150

CastleLoader – TAG-150’s MaaS loader, the entry point to the CastleRAT platform.

MuddyWater

Another malware family linked to MuddyWater is a downloader called FakeSet, which the security researchers say was used in recent infections to deliver CastleLoader. CastleLoader is sold as a service to multiple affiliates and cyber crews.

TAG-160

Four distinct threat activity clusters have been observed leveraging a malware loader known as CastleLoader, strengthening the previous assessment that the tool is offered to other threat actors under a malware-as-a-service (MaaS) model.

TAG-161

Four distinct threat activity clusters have been observed leveraging a malware loader known as CastleLoader, strengthening the previous assessment that the tool is offered to other threat actors under a malware-as-a-service (MaaS) model.

MITRE ATT&CK

CastleLoader in ATT&CK

64 distinct techniques

Techniques

64 techniques
T1562 Impair Defenses T1566 Phishing T1036 Masquerading T1204 User Execution T1059.001 PowerShell T1105 Ingress Tool Transfer T1566.002 Spearphishing Link T1059.003 Windows Command Shell T1070 Indicator Removal T1564.001 Hidden Files and Directories T1055 Process Injection T1553.002 Code Signing T1070.004 File Deletion T1071 Application Layer Protocol T1059.006 Python T1059 Command and Scripting Interpreter T1553 Subvert Trust Controls T1027.013 Encrypted/Encoded File T1204.002 Malicious File T1059.007 JavaScript T1567 Exfiltration Over Web Service T1555.003 Credentials from Web Browsers T1113 Screen Capture T1027 Obfuscated Files or Information T1218 System Binary Proxy Execution T1497 Virtualization/Sandbox Evasion T1620 Reflective Code Loading T1140 Deobfuscate/Decode Files or Information T1082 System Information Discovery T1129 Shared Modules T1036.005 Match Legitimate Resource Name or Location T1071.001 Web Protocols T1560 Archive Collected Data T1518 Software Discovery T1548 Abuse Elevation Control Mechanism T1573 Encrypted Channel T1041 Exfiltration Over C2 Channel T1055.004 Asynchronous Procedure Call T1547.009 Shortcut Modification T1555 Credentials from Password Stores T1053.005 Scheduled Task T1539 Steal Web Session Cookie T1115 Clipboard Data T1055.012 Process Hollowing T1497.001 System Checks T1564.003 Hidden Window T1480.002 Mutual Exclusion T1547.001 Registry Run Keys / Startup Folder T1106 Native API T1614 System Location Discovery T1059.010 AutoHotKey & AutoIT T1027.002 Software Packing T1195 Supply Chain Compromise T1195.001 Compromise Software Dependencies and Development Tools T1518.001 Security Software Discovery T1059.005 Visual Basic T1053 Scheduled Task/Job T1204.001 Malicious Link T1566.003 Spearphishing via Service T1071.004 DNS T1027.010 Command Obfuscation T1568 Dynamic Resolution T1585.002 Email Accounts T1583.001 Domains

Reporting

Research mentioning CastleLoader

Jul 24
Cyber Security News

FakeAgent Campaign Uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users

A malvertising campaign dubbed FakeAgent abused searches for the Claude Desktop app to deliver the SectopRAT information-stealing trojan to Windows users at at least 29 organizations. Victims who clicked sponsored Bing results were sent to a spoofed public artifact hosted on Anthropic's claude.ai domain instead of the legitimate download page, then redirected to attacker-controlled infrastructure that served a fake ClaudeDesktop.exe installer. Huntress said the activity ran from July 21 to 22 and should be treated as a full remote-access and credential-theft compromise, not a nuisance adware incident. The malware chain used DLL sideloading through a tampered libcef.dll, signed-binary proxy execution, VMProtect packing, GPU-based anti-analysis, and DirectX shader-based payload decryption to evade detection. Researchers said SectopRAT established persistence with sslconf.exe, tempdir.dll, and appcfg.dat under AppData, and retrieved command data via blockchain infrastructure tied to contract 0xc1907d7be91f95903ad66d775c397302e7dd9228; Huntress also identified 2.24.131[.]246 as a live command-and-control address. The RAT is capable of stealing browser credentials, cookies, autofill and payment data, Chromium keys, FTP credentials, Discord and messaging data, files, and passwords, and the infrastructure was linked to earlier malicious activity dating to May 2025, including domains associated with campaigns tied to StealC infrastructure seized during Operation Endgame.

Jul 23
Trojan Killer News

Fake Claude Desktop Ads Dropped SectopRAT | Trojan Killer

Jul 23
Red Canary

Intelligence Insights: July 2026 | Red Canary

Researchers reported continued activity around CastleLoader/CastleBot malware delivery chains alongside a resurgence of KongTuke, with both threats relying heavily on social-engineering lures and staged payload delivery. Red Canary said CastleLoader remained active since early 2025 and was commonly delivered through paste-and-run fake CAPTCHA or impersonation websites, while Trend Micro documented KongTuke abusing compromised WordPress sites in ClickFix-style infection flows. The campaigns reflect a broader shift toward user-assisted execution, where victims are tricked into launching malicious commands that initiate multi-stage malware retrieval. Technical analysis from IBM and Splunk tied the Castle ecosystem to a malware-as-a-service operation and detailed the tooling used after execution, including use of finger.exe to fetch batch commands, portable Python interpreters as a bring-your-own-interpreter technique, multilayer-obfuscated Python loaders, RC4-encrypted payload retrieval, and process injection into python.exe. Splunk's review of Castle RAT highlighted the client malware's tactics and ATT&CK-mapped behavior, while Red Canary noted anti-analysis checks, C2-based tasking, and detection opportunities such as repeated caret obfuscation in cmd.exe command lines. Together, the reporting shows an active loader-and-RAT ecosystem being distributed through fake verification pages and compromised web infrastructure.

Jul 23
Bleeping Computer

Fake Claude app promoted by Bing ads pushes SectopRAT malware

Jul 23
Help Net Security

How attackers hosted a fake Claude download page on the claude.ai domain - Help Net Security

Jul 23
Itsecurityguru

FakeAgent Campaign: Malicious Claude Artifact Used to Distribute SectopRAT to 29 Organisations - IT Security Guru

May 30
Huntress

Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT | Huntress

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.