CastleStealer is a .NET-based Windows information stealer used as a final-stage payload in multiple financially motivated campaigns. It harvests credentials and cookies from Chromium-family browsers and Firefox, cryptocurrency-wallet extension data, Discord and Telegram session artifacts, Steam credentials, and other browser-resident data. It can decrypt DPAPI-protected browser material, collect host fingerprints, capture desktop screenshots, and exfiltrate collected data over encrypted command-and-control communications. CastleStealer incorporates Russian-locale exclusion logic and has process-hollowing capability. It has been delivered through CastleLoader and OXLOADER chains, including ClickFix social-engineering, trojanized installer, and malvertising operations. UAT-11795 has deployed it as a follow-on payload through Starland RAT, primarily in credential- and cryptocurrency-focused activity affecting Windows users.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Depending on operator objectives, Starland RAT can deploy CastleStealer, Remcos RAT, or the previously undocumented WLDR framework.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
An obfuscated PowerShell stager was uploaded to VirusTotal on June 18, 2026. The Urutyka campaign follows CastleLoader’s established infection chain... The obfuscated PowerShell stager unpacks a second PS1 script and contacts the download server...
The downloaded MSI file executes a .bat file that launches a embedded IronPython installation... The python3 script downloads another python script from the C2 server that is responsible for injecting CastleLoader’s stage 2 shellcode.
The next-stage shellcode is a payload configured from DonutLoader ... used to wrap .NET assemblies, DLLs, and EXEs into position-independent shellcode.
6ca7a458985350ac082a9c9820d7f8d39128a4c4bda2f5d32f169a45b7b22bc6 MobaXterm_v26.1.exe ... 6ae334ce60d1a9b7fb96d1d0d0eda5ec7c2c31d3f0cf3e4d7e3056504d50043d WebEx_Client.exe ... 1a01ad25712d306f27f526332fdccf959f2de53207b54e4e80f60faa804d6cb6 FaceitInstaller_x64.exe ... f4491736743a16f1278b8ba01649ee93343764e35ae5e1c0d5e0c0e1d7e32c14 Zoom Installer
After registration, the RAT polls its C2 server approximately every 50 to 60 seconds and supports execution of shell commands, process injection of both 32-bit and 64-bit shellcode, and delivery of additional executable payloads.
These loaders resolve Windows APIs dynamically, bypass both the Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW), decrypt embedded payloads in memory, and execute them using reflective loading or PowerShell Runspaces.
Before any network activity, Starland checks whether it’s running in a sandbox. It compares the logged-on username against a hardcoded list of known sandbox service accounts... then checks the computer name against hostnames from Cuckoo, Any.Run, Joe Sandbox, and Hybrid Analysis.
The actor further supports operations with CastleStealer, a .NET infostealer targeting credentials and crypto wallets...
CastleStealer ... enumerates crypto wallet browser extensions, Discord and Telegram session files
Starland RAT performs extensive host reconnaissance, collecting hardware identifiers, operating system details, Active Directory information, installed antivirus products, desktop screenshots, and the presence of more than 40 cryptocurrency wallet applications and browser extensions.
Before any network activity, Starland checks whether it’s running in a sandbox. It compares the logged-on username against a hardcoded list of known sandbox service accounts... then checks the computer name against hostnames from Cuckoo, Any.Run, Joe Sandbox, and Hybrid Analysis.
70 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An additional payload deployed in the campaign via custom shellcode loaders, likely used for theft of victim data as part of the actor's credential and cryptocurrency-focused objectives.
A .NET infostealer delivered in CastleLoader-linked campaigns. In the Garrigin and Noidret campaigns it is installed as a downstream payload, including via a C/C++ injector that stores the .NET assembly in the .data segment and injects it into memory.
An information-stealing malware associated with the broader CastleLoader activity and referenced through C2 and download infrastructure in the IoCs.
A .NET-based stealer referenced as part of related campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.