home.social

#castleloader — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #castleloader, aggregated by home.social.

fetched live
  1. ClickFix si mette in cerca di lavoro: falsi annunci LinkedIn e Indeed per distribuire CastleLoader e RAT Python

    LevelBlue SpiderLabs analizza una nuova variante ClickFix (maggio 2026) che usa siti typosquattati imitanti LinkedIn e Indeed, il protocollo Finger e runtime Python portatili per distribuire il framework MaaS CastleLoader e un RAT Python con C2 via WebSocket. Catena d'attacco multi-stadio completamente fileless con cifratura ChaCha20/RC4.

    insicurezzadigitale.com/clickf

  2. FUD #CastleLoader being distributed via malvertizing.
    785ba9c42deca8cfc69f1aafb371802782d01bc8156a67c5c0d412c5fb3b4e33

    C2: astroflightvision[.]com

    The signer, "Soft Insanity Oy" led us to find other FUD malware from November.
    1/3

  3. 📢⚠️ A new CastleLoader variant linked to at least 469 infections, hitting US government agencies and critical sectors across Europe.

    Read: hackread.com/castleloader-vari

    #CyberSecurity #Malware #CastleLoader #USGov #Europe

  4. CastleLoader malware, known for Clickfix related attack, has been upgraded with a stealthy Python loader that helps it slip past security defenses.

    Read: hackread.com/castleloader-malw

    #CyberSecurity #Malware #InfoSec #CastleLoader #ClickFix

  5. Mentioned Malware Families: Stealc, CASTLELOADER, NightshadeC2

    Aliases for Stealc: win.stealc
    Malpedia link for Stealc: malpedia.caad.fkie.fraunhofer.
    Aliases for CASTLELOADER: win.castleloader
    Malpedia link for CASTLELOADER: malpedia.caad.fkie.fraunhofer.
    Aliases for NightshadeC2: win.nightshade_c2, CastleRAT
    Malpedia link for NightshadeC2: malpedia.caad.fkie.fraunhofer.

    #Stealc #CASTLELOADER #NightshadeC2

    Aliases provided by Malpedia.

  6. Mentioned Malware Families: Stealc, CASTLELOADER, NightshadeC2

    Aliases for Stealc: win.stealc
    Malpedia link for Stealc: malpedia.caad.fkie.fraunhofer.
    Aliases for CASTLELOADER: win.castleloader
    Malpedia link for CASTLELOADER: malpedia.caad.fkie.fraunhofer.
    Aliases for NightshadeC2: win.nightshade_c2, CastleRAT
    Malpedia link for NightshadeC2: malpedia.caad.fkie.fraunhofer.

    #Stealc #CASTLELOADER #NightshadeC2

    Aliases provided by Malpedia.

  7. Mentioned Malware Families: Stealc, CASTLELOADER, NightshadeC2

    Aliases for Stealc: win.stealc
    Malpedia link for Stealc: malpedia.caad.fkie.fraunhofer.
    Aliases for CASTLELOADER: win.castleloader
    Malpedia link for CASTLELOADER: malpedia.caad.fkie.fraunhofer.
    Aliases for NightshadeC2: win.nightshade_c2, CastleRAT
    Malpedia link for NightshadeC2: malpedia.caad.fkie.fraunhofer.

    #Stealc #CASTLELOADER #NightshadeC2

    Aliases provided by Malpedia.

  8. Mentioned Malware Families: Stealc, CASTLELOADER, NightshadeC2

    Aliases for Stealc: win.stealc
    Malpedia link for Stealc: malpedia.caad.fkie.fraunhofer.
    Aliases for CASTLELOADER: win.castleloader
    Malpedia link for CASTLELOADER: malpedia.caad.fkie.fraunhofer.
    Aliases for NightshadeC2: win.nightshade_c2, CastleRAT
    Malpedia link for NightshadeC2: malpedia.caad.fkie.fraunhofer.

    #Stealc #CASTLELOADER #NightshadeC2

    Aliases provided by Malpedia.

  9. Here's the full infection chain:

    • 198.211.110.107:79 finger connects to finger[.]cloudyape[.]com
    • 172.67.190.68:80 curl tries cloudyape[.]com/uvey.php?holt=2 but server responds with '301 Moved Permanently' and redirects to HTTPS
    • 172.67.190.68:443 dropper download
    • 172.67.190.68:80 curl gets cloudyape[.]com/uvey.php?holt=1 server redirects to HTTPS
    • 172.67.190.68:443 dropper download
    • 170.130.165.201:80 Download of file4.bin (#StealC) with fake GoogeBot user agent
    • 170.130.165.201:80 #StealC v2 C2 / exfiltration
    • 170.130.55.38:80 #CastleLoader traffic
    • 194.76.227.242:9999 #CastleRAT C2 traffic