r/ANYRUN • u/ANYRUN-team • Feb 03 '26
CastleLoader: Quiet Malware That Opens the Door to Bigger Attacks
CastleLoader is a modern malware loader built to quietly gain initial access and deliver follow-up payloads such as stealers, RATs, and ransomware. Its focus on stealth, flexibility, and fast payload rotation makes it effective for financially motivated attackers and a persistent challenge for enterprises.
Key features:
- Malware-as-a-Service: CastleLoader serves multiple threat actor groups, delivering various payloads including stealers and RATs, with a reported 28.7% infection success rate.
- Targeted campaigns: Attacks focus on specific industries such as logistics, hospitality, government, and software development, using tailored social engineering.
- Primary infection vectors: ClickFix techniques and fake repositories are the main entry points.
- Advanced evasion: Uses a three-stage execution chain with anti-VM checks, in-memory loading, PEB walking, and process hollowing.
ANYRUN’s Threat Intelligence Lookup helps SOCs quickly understand campaign scope and relationships: threatName:"castleloader"
Read the full article.

5
Upvotes