Last seven days
- First activity
- Sep 9, 2026
- Last activity
- Sep 9, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
CastleLoader is a Windows malware loader and malware-as-a-service delivery framework active since at least early 2025.
Profile source: Mallory opens in a new tabCastleLoader
CastleLoader is a Windows malware loader and malware-as-a-service delivery framework active since at least early 2025. It is commonly described as a multi-stage shellcode loader used as the initial infection component in campaigns that subsequently deploy a wide range of secondary payloads, including remote access trojans, information stealers, remote management tools, and cryptocurrency-focused theft tooling. Reported follow-on malware includes CastleRAT, CastleStealer, NetSupport RAT, SectopRAT, NeedleStealer-related components, and other commodity stealers and loaders.
CastleLoader is strongly associated with the threat cluster TAG-150 and has been characterized as an entry point to the broader CastleRAT platform. It has also been observed in multiple campaign clusters tracked under names including Urutyka, Garrigin, Noidret, and BackgroundFix. The malware has been linked to both C-based and Python-based variants, and some reporting describes it as a flexible MaaS framework designed for in-memory task execution and modular payload deployment.
Delivery is most often tied to ClickFix-style social engineering and fake verification or CAPTCHA pages that trick victims into copying and executing malicious commands. Additional observed lures include fake software installers, fake update pages, job-platform impersonation, and malicious ads or landing pages. Infection chains frequently abuse native Windows utilities and portable interpreter runtimes, including Bring-Your-Own-Interpreter approaches using Python or IronPython, to stage later components while reducing obvious on-disk artifacts.
Technically, CastleLoader has been observed retrieving encrypted tasking from command-and-control infrastructure, decrypting configuration in memory, and launching additional payloads through numerous execution methods. Reported capabilities include shellcode-based in-memory loading, process injection into legitimate processes, anti-virtualization and anti-analysis checks, host profiling, screenshot capture, and delivery of further malware. Some campaigns used digitally signed installers, Node.js-based injectors, or IronPython-based chains to execute CastleLoader stages. Its role across campaigns is primarily to establish execution and deliver secondary tooling rather than to serve as the final objective itself.
CastleLoader has been used against Windows users across broad criminal intrusion activity rather than a single vertical, with observed impacts ranging from credential and data theft to remote access and cryptocurrency theft. Its recurring use in socially engineered paste-and-run chains, fileless or low-artifact staging, and modular payload delivery has made it a notable loader in 2026 threat reporting.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
CastleLoader – TAG-150’s MaaS loader, the entry point to the CastleRAT platform.
Another malware family linked to MuddyWater is a downloader called FakeSet, which the security researchers say was used in recent infections to deliver CastleLoader. CastleLoader is sold as a service to multiple affiliates and cyber crews.
Four distinct threat activity clusters have been observed leveraging a malware loader known as CastleLoader, strengthening the previous assessment that the tool is offered to other threat actors under a malware-as-a-service (MaaS) model.
Four distinct threat activity clusters have been observed leveraging a malware loader known as CastleLoader, strengthening the previous assessment that the tool is offered to other threat actors under a malware-as-a-service (MaaS) model.
MITRE ATT&CK
Reporting
A malvertising campaign dubbed FakeAgent abused searches for the Claude Desktop app to deliver the SectopRAT information-stealing trojan to Windows users at at least 29 organizations. Victims who clicked sponsored Bing results were sent to a spoofed public artifact hosted on Anthropic's claude.ai domain instead of the legitimate download page, then redirected to attacker-controlled infrastructure that served a fake ClaudeDesktop.exe installer. Huntress said the activity ran from July 21 to 22 and should be treated as a full remote-access and credential-theft compromise, not a nuisance adware incident. The malware chain used DLL sideloading through a tampered libcef.dll, signed-binary proxy execution, VMProtect packing, GPU-based anti-analysis, and DirectX shader-based payload decryption to evade detection. Researchers said SectopRAT established persistence with sslconf.exe, tempdir.dll, and appcfg.dat under AppData, and retrieved command data via blockchain infrastructure tied to contract 0xc1907d7be91f95903ad66d775c397302e7dd9228; Huntress also identified 2.24.131[.]246 as a live command-and-control address. The RAT is capable of stealing browser credentials, cookies, autofill and payment data, Chromium keys, FTP credentials, Discord and messaging data, files, and passwords, and the infrastructure was linked to earlier malicious activity dating to May 2025, including domains associated with campaigns tied to StealC infrastructure seized during Operation Endgame.
Researchers reported continued activity around CastleLoader/CastleBot malware delivery chains alongside a resurgence of KongTuke, with both threats relying heavily on social-engineering lures and staged payload delivery. Red Canary said CastleLoader remained active since early 2025 and was commonly delivered through paste-and-run fake CAPTCHA or impersonation websites, while Trend Micro documented KongTuke abusing compromised WordPress sites in ClickFix-style infection flows. The campaigns reflect a broader shift toward user-assisted execution, where victims are tricked into launching malicious commands that initiate multi-stage malware retrieval. Technical analysis from IBM and Splunk tied the Castle ecosystem to a malware-as-a-service operation and detailed the tooling used after execution, including use of finger.exe to fetch batch commands, portable Python interpreters as a bring-your-own-interpreter technique, multilayer-obfuscated Python loaders, RC4-encrypted payload retrieval, and process injection into python.exe. Splunk's review of Castle RAT highlighted the client malware's tactics and ATT&CK-mapped behavior, while Red Canary noted anti-analysis checks, C2-based tasking, and detection opportunities such as repeated caret obfuscation in cmd.exe command lines. Together, the reporting shows an active loader-and-RAT ecosystem being distributed through fake verification pages and compromised web infrastructure.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.