CastleLoader is a Windows multi-stage shellcode loader associated with the TAG-150 malware ecosystem and observed in campaigns since early 2025. It is commonly delivered through ClickFix social-engineering lures, including fake CAPTCHA, verification, software-update, job-platform, and application-installation pages that induce victims to execute malicious PowerShell or command-shell instructions. Campaigns have also used fraudulent or digitally signed installers and malicious advertising.
CastleLoader infection chains have used the Windows Finger utility, portable CPython or IronPython runtimes, heavily obfuscated Python stages, in-memory shellcode execution, and RC4-encrypted tasking. The loader can inject its payload into a Python process, retrieve configuration and follow-on payloads from command-and-control infrastructure, and execute payloads through multiple Windows execution mechanisms. It incorporates virtualization checks and layered obfuscation intended to hinder analysis and signature-based detection. CastleLoader can capture desktop screenshots.
CastleLoader functions as an entry point for a varied payload ecosystem rather than a single-purpose final payload. Observed follow-on malware includes CastleRAT, CastleStealer, NetSupport RAT, SectopRAT, WarmCookie, HijackLoader, and NeedleStealer components. Campaign clusters tracked as Urutyka, Garrigin, and Noidret used CastleLoader to distribute remote-access tooling, information stealers, a cryptocurrency-wallet recovery-phrase spoofer, and malicious browser extensions capable of credential harvesting and browser-session theft. TAG-150 has been assessed as operating or supplying CastleLoader as part of a malware-as-a-service platform, although CastleLoader has also appeared in broader ClickFix distribution activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CastleLoader – TAG-150’s MaaS loader, the entry point to the CastleRAT platform.
Another malware family linked to MuddyWater is a downloader called FakeSet, which the security researchers say was used in recent infections to deliver CastleLoader. CastleLoader is sold as a service to multiple affiliates and cyber crews.
Four distinct threat activity clusters have been observed leveraging a malware loader known as CastleLoader, strengthening the previous assessment that the tool is offered to other threat actors under a malware-as-a-service (MaaS) model.
Four distinct threat activity clusters have been observed leveraging a malware loader known as CastleLoader, strengthening the previous assessment that the tool is offered to other threat actors under a malware-as-a-service (MaaS) model.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
In the Noidret campaign, the wallet spoofer is delivered through a Node.js-based injector and a small shellcode component.
As a result, users unknowingly execute a malicious PowerShell command, enabling malicious loaders to be launched at the next stage on the device.
The downloaded MSI file executes a .bat file that launches a embedded IronPython installation... Obfuscated .bat file invokes an IronPython shellcode injector.
The downloaded MSI file executes a .bat file that launches a embedded IronPython installation... The python3 script downloads another python script from the C2 server that is responsible for injecting CastleLoader’s stage 2 shellcode.
A NodeJS injector script ... decrypts and loads an 8 KB shellcode stub, which then reflectively injects the Rust payload.
Tasks return encrypted payloads... Each payload from a specific tasking has a unique RC4 key... delivered as a ZIP archive ... alongside ... two AES-GCM encrypted files.
Observations indicate that such campaigns make use of fake interfaces impersonating Google reCAPTCHA and Cloudflare verification pages, as well as deceptive pages associated with Google Meet, QR code services and other well-known platforms.
The python script downloads another python script from the C2 server that is responsible for injecting CastleLoader’s stage 2 shellcode... The CastleStealer payload is stored in the .data segment of the loader and gets injected into memory.
232 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
61 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named loader deployed in the infection chain preceding SloppyRAT; the content does not further describe its functionality.
A loader deployed during the observed SloppyRAT infection chain, preceding CastleRAT deployment.
A loader used to deliver CastleRAT.
A multi-stage shellcode loader used as the backbone of several related intrusion campaigns. It is delivered through staged PowerShell/IronPython/installer chains, retrieves tasking from C2 with get_tasks, and delivers downstream payloads including NetSupport RAT, CastleStealer, Lobshot, and NeedleStealer components.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.