Researchers reported continued activity around CastleLoader/CastleBot malware delivery chains alongside a resurgence of KongTuke, with both threats relying heavily on social-engineering lures and staged payload delivery. Red Canary said CastleLoader remained active since early 2025 and was commonly delivered through paste-and-run fake CAPTCHA or impersonation websites, while Trend Micro documented KongTuke abusing compromised WordPress sites in ClickFix-style infection flows. The campaigns reflect a broader shift toward user-assisted execution, where victims are tricked into launching malicious commands that initiate multi-stage malware retrieval.
Technical analysis from IBM and Splunk tied the Castle ecosystem to a malware-as-a-service operation and detailed the tooling used after execution, including use of finger.exe to fetch batch commands, portable Python interpreters as a bring-your-own-interpreter technique, multilayer-obfuscated Python loaders, RC4-encrypted payload retrieval, and process injection into python.exe. Splunk's review of Castle RAT highlighted the client malware's tactics and ATT&CK-mapped behavior, while Red Canary noted anti-analysis checks, C2-based tasking, and detection opportunities such as repeated caret obfuscation in cmd.exe command lines. Together, the reporting shows an active loader-and-RAT ecosystem being distributed through fake verification pages and compromised web infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Red Canary described CastleLoader delivery and execution techniques, including finger.exe retrieval, portable Python interpreters, obfuscated Python loaders, RC4-encrypted payload retrieval, process injection into python.exe, and a detection opportunity based on repeated caret obfuscation in cmd.exe command lines.
Red Canary highlighted a significant resurgence of KongTuke activity in its July 2026 threat prevalence roundup.
Red Canary's July 2026 roundup said ClearFake was the most prevalent threat for the third consecutive month, indicating sustained high activity through June 2026.
Red Canary reported that CastleLoader has been active since early 2025 and is commonly distributed through paste-and-run social engineering chains using fake CAPTCHA or impersonation websites.
Splunk published a blog post analyzing techniques and tactics used in Castle RAT client malware and discussing detection approaches mapped to MITRE ATT&CK.
IBM X-Force published research dissecting the CastleBot malware-as-a-service operation, documenting the threat's structure and behavior.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
redcanary.com
Open sourcesplunk.com
Open sourceibm.com
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.