Researchers reported multiple campaigns tied to the CastleLoader/CastleRAT malware ecosystem, showing operators adopting uncommon runtimes and social-engineering lures to bypass enterprise controls. ThreatDown said attackers used the Deno JavaScript runtime in what it described as the first observed abuse of Deno for malware delivery and evasion, while LevelBlue documented a related ClickFix variant that impersonated LinkedIn and Indeed through typosquatted domains and fake CAPTCHA pages to trick victims into launching malicious commands.
In the ClickFix intrusion chain, attackers abused native Windows tools including finger.exe, curl.exe, tar.exe, and cmd.exe together with portable Python runtimes to stage fileless payloads in memory. The activity culminated in deployment of CastleLoader, a malware-as-a-service framework using RC4- and ChaCha20-protected communications to fetch tasks and follow-on payloads, including a Python-based RAT that profiles victims, weakens TLS validation, communicates over WebSockets, enables interactive shell access, uploads and executes payloads, and maintains persistence with mutex and watchdog mechanisms.
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
LevelBlue reported on a May 2026 ClickFix campaign variant that impersonated LinkedIn and Indeed with typosquatted domains and fake CAPTCHA pages to trick users into running a malicious command. The campaign used Windows LOLBins and portable Python runtimes to stage fileless payloads, then deployed CastleLoader and a Python-based RAT.
ThreatDown published research describing a CastleRAT cyberattack as the first observed case abusing the Deno JavaScript runtime to evade enterprise security controls.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.