CastleStealer is a .NET-based information stealer used in financially motivated intrusion campaigns focused on credential theft and cryptocurrency-related theft on Windows systems. It has been observed as a follow-on payload delivered by malware distribution chains involving CastleLoader, OXLOADER, and Starland RAT, including campaigns that used trojanized software installers, fake update themes, ClickFix-style social engineering, and malvertising around Node.js-related lures. The malware has been associated with Russian-speaking criminal activity clusters and commonly appears alongside other tooling such as NetSupport RAT, Remcos RAT, and bespoke post-exploitation frameworks.
CastleStealer is designed to harvest sensitive data from infected hosts, including browser credentials and other browser-stored data, cryptocurrency wallet information, wallet extension data, Telegram and Discord artifacts, Steam credentials, and in some reporting browser cookies and session-related material. It also performs host profiling and can capture screenshots for exfiltration. Reported implementations include anti-analysis behavior such as exiting on Russian-language or Russian-locale systems. In some observed delivery chains, CastleStealer was executed in memory through shellcode loaders, reflective loading, APC-style injection, .NET CLR loading, or DLL side-loading, reflecting an emphasis on stealth and defense evasion.
Operationally, CastleStealer has been used as a final-stage payload after multi-stage loaders establish execution and persistence. Campaigns delivering it have targeted Windows users, with notable emphasis on cryptocurrency holders and users lured through fake installers for legitimate software or developer tools. The malware’s role in these operations is to monetize access through theft of credentials, wallet data, and other high-value user information rather than to provide broad remote administration on its own.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Depending on operator objectives, Starland RAT can deploy CastleStealer, Remcos RAT, or the previously undocumented WLDR framework.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
An obfuscated PowerShell stager was uploaded to VirusTotal on June 18, 2026. The Urutyka campaign follows CastleLoader’s established infection chain... The obfuscated PowerShell stager unpacks a second PS1 script and contacts the download server...
The downloaded MSI file executes a .bat file that launches a embedded IronPython installation... The python3 script downloads another python script from the C2 server that is responsible for injecting CastleLoader’s stage 2 shellcode.
6ca7a458985350ac082a9c9820d7f8d39128a4c4bda2f5d32f169a45b7b22bc6 MobaXterm_v26.1.exe ... 6ae334ce60d1a9b7fb96d1d0d0eda5ec7c2c31d3f0cf3e4d7e3056504d50043d WebEx_Client.exe ... 1a01ad25712d306f27f526332fdccf959f2de53207b54e4e80f60faa804d6cb6 FaceitInstaller_x64.exe ... f4491736743a16f1278b8ba01649ee93343764e35ae5e1c0d5e0c0e1d7e32c14 Zoom Installer
After registration, the RAT polls its C2 server approximately every 50 to 60 seconds and supports execution of shell commands, process injection of both 32-bit and 64-bit shellcode, and delivery of additional executable payloads.
These loaders resolve Windows APIs dynamically, bypass both the Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW), decrypt embedded payloads in memory, and execute them using reflective loading or PowerShell Runspaces.
Before any network activity, Starland checks whether it’s running in a sandbox. It compares the logged-on username against a hardcoded list of known sandbox service accounts... then checks the computer name against hostnames from Cuckoo, Any.Run, Joe Sandbox, and Hybrid Analysis.
The actor further supports operations with CastleStealer, a .NET infostealer targeting credentials and crypto wallets...
CastleStealer ... enumerates crypto wallet browser extensions, Discord and Telegram session files
Starland RAT performs extensive host reconnaissance, collecting hardware identifiers, operating system details, Active Directory information, installed antivirus products, desktop screenshots, and the presence of more than 40 cryptocurrency wallet applications and browser extensions.
Before any network activity, Starland checks whether it’s running in a sandbox. It compares the logged-on username against a hardcoded list of known sandbox service accounts... then checks the computer name against hostnames from Cuckoo, Any.Run, Joe Sandbox, and Hybrid Analysis.
67 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An additional payload deployed in the campaign via custom shellcode loaders, likely used for theft of victim data as part of the actor's credential and cryptocurrency-focused objectives.
A .NET infostealer delivered in CastleLoader-linked campaigns. In the Garrigin and Noidret campaigns it is installed as a downstream payload, including via a C/C++ injector that stores the .NET assembly in the .data segment and injects it into memory.
An information-stealing malware associated with the broader CastleLoader activity and referenced through C2 and download infrastructure in the IoCs.
A .NET-based stealer referenced as part of related campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.