CastleLoader is a Windows malware loader and multi-stage shellcode delivery framework active since at least early 2025 and associated with the TAG-150 activity cluster. It functions as an initial access and payload deployment component in campaigns that rely heavily on ClickFix-style social engineering, fake CAPTCHA or verification pages, fake updates, malicious installers, and bogus software repositories. Victims are commonly tricked into manually executing obfuscated commands, often through PowerShell or LOLBin-assisted chains, after which CastleLoader stages shellcode in memory and retrieves follow-on malware.
CastleLoader has been observed as the backbone of multiple related campaign clusters, including Urutyka, Garrigin, and Noidret, and has delivered a broad range of secondary payloads such as NetSupport RAT, CastleRAT, CastleStealer, SectopRAT, WarmCookie, HijackLoader, StealC, RedLine Stealer, Rhadamanthys Stealer, and NeedleStealer components. Reported delivery chains include C-based and Python-based CastleLoader variants, use of portable Python or IronPython runtimes, Node.js-based injection, digitally signed installers, and shellcode loaders that decrypt and inject the CastleLoader stage into memory. The malware is designed for flexible tasking and supports retrieval and execution of additional payloads with limited on-disk artifacts, complicating early detection.
Observed tradecraft includes process injection, anti-virtualization checks, host profiling, encrypted command-and-control traffic, and multiple payload launch methods using native Windows execution mechanisms. Some reporting also notes screenshot capture capability and support for extensive follow-on tasking through its command infrastructure. CastleLoader campaigns have targeted Windows users broadly, including job seekers, software downloaders, and cryptocurrency users, and have been linked to theft-focused operations as well as remote-access enablement. Recent campaign evolution shows CastleLoader being used to deliver tooling for browser session theft and cryptocurrency seed phrase theft, indicating a shift toward higher-value credential, session, and crypto-asset compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CastleLoader – TAG-150’s MaaS loader, the entry point to the CastleRAT platform.
Another malware family linked to MuddyWater is a downloader called FakeSet, which the security researchers say was used in recent infections to deliver CastleLoader. CastleLoader is sold as a service to multiple affiliates and cyber crews.
Four distinct threat activity clusters have been observed leveraging a malware loader known as CastleLoader, strengthening the previous assessment that the tool is offered to other threat actors under a malware-as-a-service (MaaS) model.
Four distinct threat activity clusters have been observed leveraging a malware loader known as CastleLoader, strengthening the previous assessment that the tool is offered to other threat actors under a malware-as-a-service (MaaS) model.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
In the Noidret campaign, the wallet spoofer is delivered through a Node.js-based injector and a small shellcode component.
As a result, users unknowingly execute a malicious PowerShell command, enabling malicious loaders to be launched at the next stage on the device.
The downloaded MSI file executes a .bat file that launches a embedded IronPython installation... Obfuscated .bat file invokes an IronPython shellcode injector.
The downloaded MSI file executes a .bat file that launches a embedded IronPython installation... The python3 script downloads another python script from the C2 server that is responsible for injecting CastleLoader’s stage 2 shellcode.
A NodeJS injector script ... decrypts and loads an 8 KB shellcode stub, which then reflectively injects the Rust payload.
Tasks return encrypted payloads... Each payload from a specific tasking has a unique RC4 key... delivered as a ZIP archive ... alongside ... two AES-GCM encrypted files.
Observations indicate that such campaigns make use of fake interfaces impersonating Google reCAPTCHA and Cloudflare verification pages, as well as deceptive pages associated with Google Meet, QR code services and other well-known platforms.
The python script downloads another python script from the C2 server that is responsible for injecting CastleLoader’s stage 2 shellcode... The CastleStealer payload is stored in the .data segment of the loader and gets injected into memory.
MITRE ATT&CK maps this behavior primarily to Credential Access (TA0006), specifically T1555 – Credentials from Password Stores and its sub-technique T1555.003 – Credentials from Web Browsers, covering theft of saved browser passwords, cookies, and autofill data.
230 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
58 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage shellcode loader used as the backbone of several related intrusion campaigns. It is delivered through staged PowerShell/IronPython/installer chains, retrieves tasking from C2 with get_tasks, and delivers downstream payloads including NetSupport RAT, CastleStealer, Lobshot, and NeedleStealer components.
A malware loader used in campaigns involving fake installers and ClickFix-style prompts to execute malicious PowerShell, gain access to Windows devices, and fetch additional payloads in later stages.
A malicious loader distributed through ClickFix campaigns after users execute attacker-supplied commands.
A multi-stage shellcode loader described as the backbone of multiple related intrusion sets over the past year.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.