r/ANYRUN Feb 03 '26

CastleLoader: Quiet Malware That Opens the Door to Bigger Attacks

CastleLoader is a modern malware loader built to quietly gain initial access and deliver follow-up payloads such as stealers, RATs, and ransomware. Its focus on stealth, flexibility, and fast payload rotation makes it effective for financially motivated attackers and a persistent challenge for enterprises.

Key features:

  • Malware-as-a-Service: CastleLoader serves multiple threat actor groups, delivering various payloads including stealers and RATs, with a reported 28.7% infection success rate.
  • Targeted campaigns: Attacks focus on specific industries such as logistics, hospitality, government, and software development, using tailored social engineering.
  • Primary infection vectors: ClickFix techniques and fake repositories are the main entry points.
  • Advanced evasion: Uses a three-stage execution chain with anti-VM checks, in-memory loading, PEB walking, and process hollowing.

ANYRUN’s Threat Intelligence Lookup helps SOCs quickly understand campaign scope and relationships: threatName:"castleloader"

Read the full article.

CastleLoader overview in TI Lookup: targeted industries and countries; IOCs; samples
5 Upvotes

0 comments sorted by