CastleLoader Analysis
Essential information
- Published
- 13/08/2025 11:57
- Modified
- 13/08/2025 15:47
- Tags
- 2025-08-13 autoit c2 castleloader deerstealer github hijackloader information stealers malware loader netsupport rat payload delivery phishing powershell rats redline sectoprat stealc u.s. government
- Related entities
- 18 techniques (mitre), 7 malware, 2 others
Description
CastleLoader, a versatile malware loader, has infected 469 devices since May 2025 using Cloudflare-themed ClickFix phishing and fake GitHub repositories. It delivers information stealers and RATs, with a 28.7% infection rate. The malware employs sophisticated techniques, including PowerShell and AutoIT scripts, to load shellcode into memory and connect to C2 servers. CastleLoader's modular design allows deployment of multiple payloads, including StealC, RedLine, NetSupport RAT, DeerStealer, HijackLoader, and SectopRAT. Its campaigns target U.S. government entities and use legitimate file-sharing services and compromised websites for payload retrieval, enhancing resilience against takedowns.