CastleLoader, also known as CastleBot, is a multi-stage malware loader targeting Windows systems and active since early 2025. Associated with TAG-150's malware-as-a-service ecosystem, it retrieves and executes additional payloads, including CastleRAT, NetSupport Manager, CastleStealer, SectopRAT, and NeedleStealer. Its role is malware delivery and execution; information theft and remote-control capabilities depend on the deployed payloads.
Distribution commonly uses ClickFix social engineering, including fake CAPTCHA pages that persuade victims to paste and execute malicious commands. Campaigns have also used malicious advertisements, job-platform impersonation, fake software installers, and deceptive update pages. Infection chains employ obfuscated PowerShell or batch commands, sometimes abusing the Windows Finger utility to retrieve subsequent stages. Legitimate CPython, IronPython, and Node.js runtimes support staged execution and shellcode loading.
CastleLoader delivery chains use layered encoding, compression, and RC4-encrypted payloads. The loader can be injected into a Python process and communicate with command-and-control infrastructure for configuration, tasking, and additional malware. In-memory execution limits on-disk artifacts. CastleLoader supports 14 payload launch methods through Windows APIs and command-line utilities, performs processor-based checks for virtualized environments, and can capture desktop screenshots through Windows graphics APIs.
Related campaigns tracked as Urutyka, Garrigin, and Noidret use varying payload combinations. Newer variants have appeared in digitally signed malicious installers, while the Noidret campaign expanded delivery to cryptocurrency-wallet spoofers and malicious browser-extension installers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CastleLoader – TAG-150’s MaaS loader, the entry point to the CastleRAT platform.
Another malware family linked to MuddyWater is a downloader called FakeSet, which the security researchers say was used in recent infections to deliver CastleLoader. CastleLoader is sold as a service to multiple affiliates and cyber crews.
Four distinct threat activity clusters have been observed leveraging a malware loader known as CastleLoader, strengthening the previous assessment that the tool is offered to other threat actors under a malware-as-a-service (MaaS) model.
Four distinct threat activity clusters have been observed leveraging a malware loader known as CastleLoader, strengthening the previous assessment that the tool is offered to other threat actors under a malware-as-a-service (MaaS) model.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
In the Noidret campaign, the wallet spoofer is delivered through a Node.js-based injector and a small shellcode component.
As a result, users unknowingly execute a malicious PowerShell command, enabling malicious loaders to be launched at the next stage on the device.
The downloaded MSI file executes a .bat file that launches a embedded IronPython installation... Obfuscated .bat file invokes an IronPython shellcode injector.
“It then retrieves IronPython, which runs compressed and Base64-encoded code that downloads later stages.”
A NodeJS injector script ... decrypts and loads an 8 KB shellcode stub, which then reflectively injects the Rust payload.
Tasks return encrypted payloads... Each payload from a specific tasking has a unique RC4 key... delivered as a ZIP archive ... alongside ... two AES-GCM encrypted files.
Observations indicate that such campaigns make use of fake interfaces impersonating Google reCAPTCHA and Cloudflare verification pages, as well as deceptive pages associated with Google Meet, QR code services and other well-known platforms.
The python script downloads another python script from the C2 server that is responsible for injecting CastleLoader’s stage 2 shellcode... The CastleStealer payload is stored in the .data segment of the loader and gets injected into memory.
Arctic Wolf also recommends application allowlisting and preventing unsigned or unexpectedly signed binaries from running in user-writable locations.
233 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
67 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware loader launched by a Python script that victims were socially engineered into executing during the April 2026 ClickFix campaign associated with CastleStealer. The content provides no further technical details about its capabilities.
Loader used in CastleStealer's April 2026 delivery chain. ClickFix social engineering delivered a Python script that executed CastleLoader. Analysts assess that the loaders delivering CastleStealer appear to be developed in-house, with substantial anti-analysis and stealth capabilities; the content does not specify CastleLoader's individual implementation techniques.
CastleLoader is mentioned only in the title of a supporting reference as payload delivered through a ClickFix campaign; the detection itself is not specifically about this malware.
A loader deployed in a ClickFix sub-campaign; no further capabilities are described.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.