Castle RAT is a Windows remote access trojan used in targeted intrusion campaigns to provide persistent interactive access to compromised hosts. Reported capabilities include remote command execution, file exfiltration, keystroke logging, and screen capture. It has also been associated with stealth-oriented tradecraft such as anomalous browser launches, suspicious inter-process communication, and abuse of Windows internals for privilege-related operations.
Castle RAT has been observed delivered through phishing and malicious installers. In more recent intrusion chains, operators used malicious MSI packages together with VBScript and PowerShell staging to deploy additional components, including Deno-based JavaScript payloads executed in memory. These campaigns abused legitimate Windows utilities and alternative runtime environments to reduce visibility, establish persistence, and maintain command-and-control while avoiding more traditional malware execution patterns.
A notable behavior associated with Castle RAT is bypass of Windows User Account Control through abuse of the AppInfo RPC service and a handle obtained from ComputerDefaults.exe. Related activity has also included registry-based autorun persistence, host fingerprinting, retrieval of follow-on payloads, and post-compromise discovery and credential-access actions in some intrusions. Castle RAT activity has been linked to long-term access operations in which attackers stage collection and exfiltration after initial compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Castle RAT provides adversaries with capabilities such as remote command execution...
Detectable indicators include anomalous process parentage (legitimate browsers or system utilities spawned by unknown executables), uncommon command-line switches, persistent autorun entries, and suspicious network connections to uncommon domains or dynamic DNS.
This technique is commonly used to escalate privileges or bypass UAC by inheriting or injecting elevated tokens or handles. The detection focuses on non-standard use of DuplicateHandle or token duplication where process, thread, or token handles are copied into the context of trusted, signed utilities.
The following analytic detects suspicious handle duplication activity targeting known Windows utilities such as ComputerDefaults.exe, Eventvwr.exe, and others. This technique is commonly used to escalate privileges or bypass UAC by inheriting or injecting elevated tokens or handles.
Detectable indicators include anomalous process parentage (legitimate browsers or system utilities spawned by unknown executables), uncommon command-line switches, persistent autorun entries, and suspicious network connections to uncommon domains or dynamic DNS.
This technique is commonly used to escalate privileges or bypass UAC by inheriting or injecting elevated tokens or handles. The detection focuses on non-standard use of DuplicateHandle or token duplication where process, thread, or token handles are copied into the context of trusted, signed utilities.
The following analytic detects suspicious handle duplication activity targeting known Windows utilities such as ComputerDefaults.exe, Eventvwr.exe, and others. This technique is commonly used to escalate privileges or bypass UAC by inheriting or injecting elevated tokens or handles.
Castle RAT provides adversaries with capabilities such as remote command execution, file exfiltration, keystroke logging, and screen capture...
Application Layer Protocol: Web Protocols – T1071.001 Another common theme is the use of protocols such as HTTP for C2 communications.
MITRE ATT&CK Technique Malware Families T1105 0bj3ctivity Stealer, Agent Tesla, Amadey, AsyncRAT, Castle RAT, DarkCrystal RAT, gh0st RAT, Lokibot, njRAT, PlugX, QuasarRAT, RedLine Stealer, Remcos
ThreatDown documented a similar intrusion chain involving Deno-based JavaScript execution and the delivery of Castle RAT... In case 4, the threat actor subsequently retrieved PowerShell scripts and executed PowerShell via a legitimate PsExec binary to gain a shell with SYSTEM privileges.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan delivered in a similar Deno-abuse intrusion chain referenced for comparison.
Associated Analytic Story ... Castle RAT ...
Castle RAT is referenced as a named remote access trojan associated with the analytic story for suspicious scheduled task activity.
Associated Analytic Story Braodo Stealer [[URL_48af0601_56]] Castle RAT [[URL_48af0601_57]] Hellcat Ransomware [[URL_48af0601_58]] Scattered Lapsus$ Hunters [[URL_48af0601_59]]
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.