CastleLoader is a Windows-focused modular malware loader and loader-as-a-service platform active since early 2025. It is commonly described as a multi-stage shellcode loader used to establish initial footholds and deliver a wide range of secondary payloads, including remote access trojans, information stealers, and other post-compromise tooling such as NetSupport RAT, CastleStealer, SectopRAT, LummaC2, StealC, RedLine, Rhadamanthys, DeerStealer, and CastleRAT. The malware has been linked to the threat actor tracked as TAG-150, later renamed GrayBravo, and has also been associated in some reporting with MuddyWater through shared certificate artifacts and delivery overlap. CastleLoader has also been characterized as being sold or operated in a malware-as-a-service model serving multiple affiliates or intrusion clusters.
CastleLoader is notable for heavily staged, memory-oriented execution chains designed to reduce on-disk visibility and complicate detection. Observed delivery chains use obfuscated PowerShell, batch scripts, shellcode loaders, embedded or portable Python and IronPython runtimes, Node.js-based injectors, and NSIS or MSI installers. Campaigns frequently culminate in in-memory decryption and execution of CastleLoader shellcode, after which the loader contacts command-and-control infrastructure for configuration, tasking, host profiling, and retrieval of additional payloads. Reported implementations use encrypted tasking and protected communications, including RC4 and ChaCha-family encryption, and support multiple payload launch methods. Anti-analysis features include virtual-machine checks, API hashing, stack-string or string obfuscation, direct or low-level system-call usage, reflective loading, and process injection. Some campaigns also used signed installers and oversized junk-padded packages to evade reputation and sandbox-based defenses.
The malware is strongly associated with ClickFix and related paste-and-run social-engineering campaigns. Victims are lured through fake CAPTCHA, fake verification, fake update, job-platform impersonation, bogus software installers, and fake utility or image-editing sites, then tricked into executing malicious commands themselves. Additional observed distribution methods include phishing, malvertising-linked impersonation flows, and fraudulent GitHub repositories masquerading as legitimate software. Several campaigns abused native Windows utilities such as finger.exe, curl.exe, tar.exe, cmd.exe, PowerShell, and msiexec, as well as bring-your-own-interpreter techniques using legitimate Python distributions.
Operationally, CastleLoader functions as a flexible first-stage access and payload-delivery framework rather than a single-purpose stealer or RAT. It has been used across campaigns targeting enterprises and individual users, with reported victim sectors including government, critical infrastructure, IT, logistics, and broader business environments. Recent campaign evolution shows a shift from broad credential theft toward more specialized follow-on theft of cryptocurrency wallet recovery phrases, browser data, and active browser sessions through delivered payloads such as NeedleStealer components. This positions CastleLoader as a central access-and-delivery component in financially motivated intrusion activity, especially where operators want modular payload deployment, defense evasion, and low-artifact execution on Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CastleStealer is a .NET information stealer that was recently distributed alongside CastleLoader through a ClickFix-style lure masquerading as a free image-editing tool as part of a campaign codenamed BackgroundFix.
Another malware family linked to MuddyWater is a downloader called FakeSet, which the security researchers say was used in recent infections to deliver CastleLoader. CastleLoader is sold as a service to multiple affiliates and cyber crews.
Four distinct threat activity clusters have been observed leveraging a malware loader known as CastleLoader, strengthening the previous assessment that the tool is offered to other threat actors under a malware-as-a-service (MaaS) model.
Four distinct threat activity clusters have been observed leveraging a malware loader known as CastleLoader, strengthening the previous assessment that the tool is offered to other threat actors under a malware-as-a-service (MaaS) model.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
In the Noidret campaign, the wallet spoofer is delivered through a Node.js-based injector and a small shellcode component.
The operation starts with fake software installers and ClickFix-style prompts that pressure victims into running harmful PowerShell commands.
The downloaded MSI file executes a .bat file that launches a embedded IronPython installation... Obfuscated .bat file invokes an IronPython shellcode injector.
The downloaded MSI file executes a .bat file that launches a embedded IronPython installation... The python3 script downloads another python script from the C2 server that is responsible for injecting CastleLoader’s stage 2 shellcode.
A NodeJS injector script ... decrypts and loads an 8 KB shellcode stub, which then reflectively injects the Rust payload.
used caret-obfuscated commands ... The shellcode loader used triple-layer encoding (Base64, zlib, UTF-32) and Cyrillic character substitution for obfuscation and fetched an RC4-encrypted payload
Tasks return encrypted payloads... Each payload from a specific tasking has a unique RC4 key... delivered as a ZIP archive ... alongside ... two AES-GCM encrypted files.
the extension posed as an ad blocker while quietly establishing persistent access to browser data and sessions
the decoded Python script is a download cradle that pulls CastleLoader Stage 2 shellcode... CastleLoader injects into memory... The CastleStealer payload is stored in the .data segment of the loader and gets injected into memory.
Deletes RunMRU registry key to cover its tracks: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU
CastleLoader supports 14 launch methods for executing payloads, including ... rundll32.exe ... msiexec.exe
MITRE ATT&CK maps this behavior primarily to Credential Access (TA0006), specifically T1555 – Credentials from Password Stores and its sub-technique T1555.003 – Credentials from Web Browsers, covering theft of saved browser passwords, cookies, and autofill data.
228 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
53 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware loader used in campaigns involving fake installers and ClickFix-style prompts to execute malicious PowerShell, gain access to Windows devices, and fetch additional payloads in later stages.
A multi-stage shellcode loader described as the backbone of multiple related intrusion sets over the past year.
A multi-stage shellcode loader used as the backbone of several related intrusion campaigns. It is delivered through staged PowerShell/IronPython/installer chains, retrieves tasking from C2 via get_tasks, and delivers downstream payloads including NetSupport RAT, CastleStealer, Lobshot, and NeedleStealer components.
A loader used to deliver Lumma, especially via ClickFix fake-CAPTCHA social-engineering chains. The report describes it as surging since late 2025 and central to current Lumma campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.