Arctic Wolf Labs reported that threat activity built around CastleLoader, a multi-stage shellcode loader, has expanded into multiple related malware campaigns. The company said CastleLoader has supported several intrusion sets over the past year and is now being observed alongside additional tooling, including the .NET-based CastleStealer and PythonRAT, indicating a broader and evolving malware ecosystem rather than a single isolated payload.
The report also highlights a newly identified connection to NeedleStealer, extending earlier public reporting on related components by Huntress and LevelBlue. The findings suggest operators are reusing and adapting established malware families and delivery chains, giving defenders new indicators for tracking campaigns tied to CastleLoader and its associated stealers and remote-access tooling.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
Arctic Wolf Labs reported on a cluster of malware campaigns centered on the multi-stage CastleLoader shellcode loader and connected the activity to previously documented tooling including CastleStealer and PythonRAT, while highlighting a newly noted NeedleStealer connection.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 45 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
arcticwolf.com
Open sourcecybersecuritynews.com
Open sourcegithub.com
Open sourcemalware.news
Open sourcearcticwolf.com
Open sourcebeelzebub.ai
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.