216.73.217.22

CastleLoader Analysis

· Published 13/08/2025 11:57 · Modified 13/08/2025 15:47

Export JSON

Essential information

Published
13/08/2025 11:57
Modified
13/08/2025 15:47
Tags
2025-08-13 autoit c2 castleloader deerstealer github hijackloader information stealers malware loader netsupport rat payload delivery phishing powershell rats redline sectoprat stealc u.s. government
Related entities
18 techniques (mitre), 7 malware, 2 others

Description

, a versatile , has infected 469 devices since May 2025 using Cloudflare-themed ClickFix and fake repositories. It delivers and , with a 28.7% infection rate. The malware employs sophisticated techniques, including and scripts, to load shellcode into memory and connect to servers. 's modular design allows deployment of multiple payloads, including , , , , , and . Its campaigns target entities and use legitimate file-sharing services and compromised websites for payload retrieval, enhancing resilience against takedowns.

External references