CastleLoader is a modular multi-stage malware loader and loader-as-a-service platform active since early 2025. It is used as an initial infection component to stage and execute additional payloads in memory, and has been observed delivering a wide range of secondary malware including NetSupport RAT, CastleStealer, CastleRAT, LummaC2, SectopRAT, StealC, RedLine, Rhadamanthys, DeerStealer, WarmCookie, and other stealers and remote-access tooling. Reporting consistently describes it as a shellcode-based loader with strong emphasis on obfuscation, anti-analysis, and flexible payload execution.
CastleLoader is most commonly associated with ClickFix-style social engineering chains in which victims are tricked into manually executing malicious commands from fake verification or CAPTCHA pages. It has also been distributed through bogus GitHub repositories, job-platform impersonation lures, fake software and utility sites, trojanized installers, signed NSIS or MSI packages, and related phishing-driven delivery chains. Observed staging frequently abuses native Windows utilities and legitimate runtimes, including PowerShell, batch scripts, finger.exe, curl.exe, tar.exe, and portable Python or IronPython interpreters, to retrieve and launch later stages while reducing detection.
Technically, CastleLoader commonly executes through multi-layered shellcode and reflective loading chains. Observed variants decrypt payloads in memory, inject into benign processes such as python.exe, resolve APIs dynamically through hashing, use stack-string or similar string obfuscation, and communicate with command-and-control infrastructure using encrypted tasking. RC4-encrypted payload retrieval and ChaCha20-protected command traffic have both been documented. Variants also support numerous payload launch methods, host profiling, screenshot capture, anti-virtualization checks, and execution-status reporting. Some campaigns used both C-based and Python-based CastleLoader variants, and signed installer-based distribution has also been observed.
CastleLoader is closely linked to the threat cluster tracked as TAG-150, later renamed GrayBravo, which appears to have developed or operated CastleLoader alongside CastleBot and CastleRAT. The malware has also been linked in some reporting to MuddyWater through certificate overlap and delivery relationships, though CastleLoader is additionally described as a service used by multiple affiliates or crews, which complicates attribution. Operational use has targeted a broad victim set, including enterprises, government-related organizations, critical infrastructure, IT, logistics, and users reached through mass social-engineering campaigns.
CastleLoader’s role in modern intrusion chains is primarily as a stealthy initial-stage execution and delivery framework. Its recurring use in ClickFix campaigns, fileless or memory-resident execution paths, anti-analysis features, and ability to deploy diverse follow-on malware make it a significant malware distribution platform rather than a single-purpose payload.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CastleStealer is a .NET information stealer that was recently distributed alongside CastleLoader through a ClickFix-style lure masquerading as a free image-editing tool as part of a campaign codenamed BackgroundFix.
Another malware family linked to MuddyWater is a downloader called FakeSet, which the security researchers say was used in recent infections to deliver CastleLoader. CastleLoader is sold as a service to multiple affiliates and cyber crews.
Four distinct threat activity clusters have been observed leveraging a malware loader known as CastleLoader, strengthening the previous assessment that the tool is offered to other threat actors under a malware-as-a-service (MaaS) model.
Four distinct threat activity clusters have been observed leveraging a malware loader known as CastleLoader, strengthening the previous assessment that the tool is offered to other threat actors under a malware-as-a-service (MaaS) model.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
CastleLoader queries its C2 via a get_tasks command. Tasks return encrypted payloads...
An obfuscated PowerShell stager was uploaded to VirusTotal on June 18, 2026. The Urutyka campaign follows CastleLoader’s established infection chain... The obfuscated PowerShell stager unpacks a second PS1 script and contacts the download server...
The downloaded MSI file executes a .bat file that launches a embedded IronPython installation... Obfuscated .bat file invokes an IronPython shellcode injector.
The downloaded MSI file executes a .bat file that launches a embedded IronPython installation... The python3 script downloads another python script from the C2 server that is responsible for injecting CastleLoader’s stage 2 shellcode.
A NodeJS injector script ... decrypts and loads an 8 KB shellcode stub, which then reflectively injects the Rust payload.
used caret-obfuscated commands ... The shellcode loader used triple-layer encoding (Base64, zlib, UTF-32) and Cyrillic character substitution for obfuscation and fetched an RC4-encrypted payload
Tasks return encrypted payloads... Each payload from a specific tasking has a unique RC4 key... delivered as a ZIP archive ... alongside ... two AES-GCM encrypted files.
downloads and executes traffic1.exe, spoofing a Microsoft Edge update... Drop path: %ProgramData%\EdgeUpdate\traffic1.exe (masquerades as a Windows EdgeUpdate directory)
the decoded Python script is a download cradle that pulls CastleLoader Stage 2 shellcode... CastleLoader injects into memory... The CastleStealer payload is stored in the .data segment of the loader and gets injected into memory.
Deletes RunMRU registry key to cover its tracks: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU
CastleLoader supports 14 launch methods for executing payloads, including ... rundll32.exe ... msiexec.exe
MITRE ATT&CK maps this behavior primarily to Credential Access (TA0006), specifically T1555 – Credentials from Password Stores and its sub-technique T1555.003 – Credentials from Web Browsers, covering theft of saved browser passwords, cookies, and autofill data.
226 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
52 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage shellcode loader described as the backbone of multiple related intrusion sets over the past year.
A multi-stage shellcode loader used as the backbone of several related intrusion campaigns. It is delivered through staged PowerShell/IronPython/installer chains, retrieves tasking from C2 via get_tasks, and delivers downstream payloads including NetSupport RAT, CastleStealer, Lobshot, and NeedleStealer components.
A loader used to deliver Lumma, especially via ClickFix fake-CAPTCHA social-engineering chains. The report describes it as surging since late 2025 and central to current Lumma campaigns.
Malware loader active since early 2025 and frequently distributed via paste-and-run campaigns. It retrieves and injects its payload into python.exe, contacts C2 servers for configuration and tasking, supports multiple payload launch methods, uses anti-analysis checks for virtual environments, and can capture screenshots.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.