CastleRAT is a modular remote-access trojan associated with the TAG-150 malware ecosystem, also referenced as NightShadeC2 and, for an early Python variant, PyNightshade. It has been observed in compiled Python and C implementations targeting Windows systems. Core functions include host reconnaissance, remote command execution through CMD and PowerShell, downloading and executing additional payloads, and communication using a custom RC4-encrypted protocol. The C variant additionally supports keylogging and screen capture. CastleRAT can use dead-drop resolution, including Steam Community content, to obtain operational infrastructure.
CastleRAT is commonly deployed as a later-stage payload by CastleLoader through ClickFix and fake-update social-engineering campaigns; it has also been associated with ClearFake delivery activity. Observed campaigns have used it to proxy live browser sessions and facilitate account-takeover attempts using harvested browser credentials. Reporting also attributes browser credential theft, bypass of Chrome app-bound cookie protection under certain conditions, Hidden VNC, and SOCKS5 proxying to TAG-150 CastleRAT builds.
TAG-150 has operated CastleRAT since at least 2025. Iranian state-linked MuddyWater has been assessed as a customer of the Russian-speaking TAG-150 malware-as-a-service ecosystem, using CastleRAT in espionage operations against Israeli targets and organizations in defense, energy, government, and telecommunications sectors across the Middle East, United States, and Europe.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Israeli-Focused Targeting Set Targets include Israeli IP ranges, Laravel web applications, and FortiOS systems. ... MITRE ATT&CK ID Technique ... T1190 CVE-2024-55591, CVE-2024-23113, CVE-2026-1281 | This report documents a direct operational link between the exposed infrastructure of Iranian threat actor MuddyWater and TAG-150 CastleRAT malware – a modular malware-as-a-service (MaaS) platform developed by Russian-speaking cybercriminals.
Israeli-Focused Targeting Set Targets include Israeli IP ranges, Laravel web applications, and FortiOS systems. ... MITRE ATT&CK ID Technique ... T1190 CVE-2024-55591, CVE-2024-23113, CVE-2026-1281 | This report documents a direct operational link between the exposed infrastructure of Iranian threat actor MuddyWater and TAG-150 CastleRAT malware – a modular malware-as-a-service (MaaS) platform developed by Russian-speaking cybercriminals.
Israeli-Focused Targeting Set Targets include Israeli IP ranges, Laravel web applications, and FortiOS systems. ... MITRE ATT&CK ID Technique ... T1190 CVE-2024-55591, CVE-2024-23113, CVE-2026-1281 | This report documents a direct operational link between the exposed infrastructure of Iranian threat actor MuddyWater and TAG-150 CastleRAT malware – a modular malware-as-a-service (MaaS) platform developed by Russian-speaking cybercriminals.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This report documents a direct operational link between the exposed infrastructure of Iranian threat actor MuddyWater and TAG-150 CastleRAT malware – a modular malware-as-a-service (MaaS) platform developed by Russian-speaking cybercriminals.
This report documents a direct operational link between the exposed infrastructure of Iranian threat actor MuddyWater and TAG-150 CastleRAT malware – a modular malware-as-a-service (MaaS) platform developed by Russian-speaking cybercriminals.
...Velvet Tempest ... used a ClickFix lure ... to drop payloads like DonutLoader and CastleRAT.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
Actor attempts logins to financial-institution websites using exfiltrated browser credentials
MITRE ATT&CK ID Technique T1190 CVE-2024-55591, CVE-2024-23113, CVE-2026-1281
These incidents have all included the use of finger.exe as the initial retrieval mechanism with the majority using caret (^) obfuscation on the command string.
`reset.ps1` was found on the MuddyWater-attributed C2 server ... This PowerShell script installs Node.js, AES-decrypts an embedded payload, and deploys the ChainShell pair
“It then retrieves IronPython, which runs compressed and Base64-encoded code that downloads later stages.”
ChainShell is a thin execution shell, the server sends JavaScript via `new Function()` and the agent executes and returns results via `serverSend()`.
These incidents have all included the use of finger.exe as the initial retrieval mechanism with the majority using caret (^) obfuscation on the command string.
Analysis of an exposed C2 server revealed 15 malware samples, including CastleRAT builds hidden in steganographic image files and additional JavaScript-based RAT variants.
The Blackpoint APG is currently tracking a campaign that uses ClickFix-style lures fake AMD/Intel software updater prompts to trick users into executing a malicious loader.
CastleRAT is a remote access trojan with several capabilities including keylogging
By adopting CastleRAT and ChainShell, MuddyWater gains access to advanced capabilities including: Hidden Virtual Network Computing (HVNC) for stealth system control Credential theft and Chrome cookie decryption
«CastleRAT» est un cheval de Troie d’accès à distance, conçu pour offrir un contrôle complet d’un système compromis via un serveur C2.
used CastleRAT to proxy the replica’s live browser session, attempting logins against financial-institution websites directly from the compromised workstation
At the time of publication, Phexia is unique from other macOS stealers in its use of dead drop resolution with Telegram, Steam, and blockchain smart contracts to discover command and control (C2) domains for communication.
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
39 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote-access trojan downloaded as a later stage in the SloppyRAT ClickFix infection chain.
A named remote-access payload downloaded as a later stage in the same ClickFix delivery chain. The content provides no further functional details.
A named remote-access trojan delivered as part of the same multi-stage infection chain; the content does not provide further functional details.
A remote-access trojan ultimately deployed in the observed SloppyRAT infection chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.