CASTLETAP is a malware implant documented in ATT&CK that can initiate command-and-control communications over an SSL socket and can create a raw promiscuous socket to sniff network traffic. The content links CASTLETAP to Chinese threat actor activity involving exploitation of security flaws in Fortinet appliances, alongside other implants such as BOLDMOVE and THINCRUST. High-confidence behavior described in the source includes SSL-encrypted C2 and packet-sniffing capability for network traffic collection. The available content does not provide additional confirmed details on specific infection workflow, persistence mechanisms, or victim sectors beyond its association with Fortinet appliance exploitation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
"N-day security vulnerabilities in its software, such as CVE-2022-42475 and CVE-2023-27997, are being exploited by multiple activity clusters..." and "armed forces was infiltrated... by exploiting known flaws in Fortinet FortiGate devices to deliver a backdoor called COATHANGER."
The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'
Sandworm Team used BlackEnergy’s network sniffer module to discover user credentials being sent over the network...; APT33 has used SniffPass to collect credentials by sniffing network traffic; ArcaneDoor included network packet capture and sniffing...; multiple tools (CASTLETAP, Impacket, Empire, PoshC2, etc.) described as sniffing/packet capture.
Sandworm Team used BlackEnergy’s network sniffer module to discover user credentials being sent over the network...; APT33 has used SniffPass to collect credentials by sniffing network traffic; ArcaneDoor included network packet capture and sniffing...; multiple tools (CASTLETAP, Impacket, Empire, PoshC2, etc.) described as sniffing/packet capture.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... CASTLETAP ... (v1.0) ...
CASTLETAP (v1.0)
Implant/backdoor associated with Chinese threat actors, delivered via exploitation of Fortinet appliance vulnerabilities (including zero-days) to establish access on targeted devices.
Malware with capability to sniff network traffic via raw promiscuous sockets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.