#castleloader — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #castleloader, aggregated by home.social.
-
ClickFix si mette in cerca di lavoro: falsi annunci LinkedIn e Indeed per distribuire CastleLoader e RAT Python
LevelBlue SpiderLabs analizza una nuova variante ClickFix (maggio 2026) che usa siti typosquattati imitanti LinkedIn e Indeed, il protocollo Finger e runtime Python portatili per distribuire il framework MaaS CastleLoader e un RAT Python con C2 via WebSocket. Catena d'attacco multi-stadio completamente fileless con cifratura ChaCha20/RC4. -
FUD #CastleLoader being distributed via malvertizing.
785ba9c42deca8cfc69f1aafb371802782d01bc8156a67c5c0d412c5fb3b4e33C2: astroflightvision[.]com
The signer, "Soft Insanity Oy" led us to find other FUD malware from November.
1/3 -
LummaStealer Is Getting a Second Life Alongside CastleLoader
#LummaStealer #CastleLoader
https://www.bitdefender.com/en-us/blog/labs/lummastealer-second-life-castleloader -
📢⚠️ A new CastleLoader variant linked to at least 469 infections, hitting US government agencies and critical sectors across Europe.
Read: https://hackread.com/castleloader-variant-infections-critical-sectors/
-
CastleLoader Malware Now Uses Python Loader to Bypass Security https://hackread.com/castleloader-malware-python-loader-bypass-security/ #BlackpointCyber #Cybersecurity #CastleLoader #CyberAttack #Security #ClickFix #Malware #Windows #Python
-
CastleLoader malware, known for Clickfix related attack, has been upgraded with a stealthy Python loader that helps it slip past security defenses.
Read: https://hackread.com/castleloader-malware-python-loader-bypass-security/
-
Mentioned Malware Families: Stealc, CASTLELOADER, NightshadeC2
Aliases for Stealc: win.stealc
Malpedia link for Stealc: https://malpedia.caad.fkie.fraunhofer.de/details/win.stealc
Aliases for CASTLELOADER: win.castleloader
Malpedia link for CASTLELOADER: https://malpedia.caad.fkie.fraunhofer.de/details/win.castleloader
Aliases for NightshadeC2: win.nightshade_c2, CastleRAT
Malpedia link for NightshadeC2: https://malpedia.caad.fkie.fraunhofer.de/details/win.nightshade_c2#Stealc #CASTLELOADER #NightshadeC2
Aliases provided by Malpedia.
-
Mentioned Malware Families: Stealc, CASTLELOADER, NightshadeC2
Aliases for Stealc: win.stealc
Malpedia link for Stealc: https://malpedia.caad.fkie.fraunhofer.de/details/win.stealc
Aliases for CASTLELOADER: win.castleloader
Malpedia link for CASTLELOADER: https://malpedia.caad.fkie.fraunhofer.de/details/win.castleloader
Aliases for NightshadeC2: win.nightshade_c2, CastleRAT
Malpedia link for NightshadeC2: https://malpedia.caad.fkie.fraunhofer.de/details/win.nightshade_c2#Stealc #CASTLELOADER #NightshadeC2
Aliases provided by Malpedia.
-
Mentioned Malware Families: Stealc, CASTLELOADER, NightshadeC2
Aliases for Stealc: win.stealc
Malpedia link for Stealc: https://malpedia.caad.fkie.fraunhofer.de/details/win.stealc
Aliases for CASTLELOADER: win.castleloader
Malpedia link for CASTLELOADER: https://malpedia.caad.fkie.fraunhofer.de/details/win.castleloader
Aliases for NightshadeC2: win.nightshade_c2, CastleRAT
Malpedia link for NightshadeC2: https://malpedia.caad.fkie.fraunhofer.de/details/win.nightshade_c2#Stealc #CASTLELOADER #NightshadeC2
Aliases provided by Malpedia.
-
Mentioned Malware Families: Stealc, CASTLELOADER, NightshadeC2
Aliases for Stealc: win.stealc
Malpedia link for Stealc: https://malpedia.caad.fkie.fraunhofer.de/details/win.stealc
Aliases for CASTLELOADER: win.castleloader
Malpedia link for CASTLELOADER: https://malpedia.caad.fkie.fraunhofer.de/details/win.castleloader
Aliases for NightshadeC2: win.nightshade_c2, CastleRAT
Malpedia link for NightshadeC2: https://malpedia.caad.fkie.fraunhofer.de/details/win.nightshade_c2#Stealc #CASTLELOADER #NightshadeC2
Aliases provided by Malpedia.
-
Here's the full infection chain:
198.211.110.107:79finger connects to finger[.]cloudyape[.]com172.67.190.68:80curl triescloudyape[.]com/uvey.php?holt=2but server responds with '301 Moved Permanently' and redirects to HTTPS172.67.190.68:443dropper download172.67.190.68:80curl getscloudyape[.]com/uvey.php?holt=1server redirects to HTTPS172.67.190.68:443dropper download170.130.165.201:80Download offile4.bin(#StealC) with fakeGoogeBotuser agent170.130.165.201:80#StealC v2 C2 / exfiltration170.130.55.38:80#CastleLoader traffic194.76.227.242:9999#CastleRAT C2 traffic
-
CastleLoader Malware Infects 469 Devices Using Fake GitHub Repos and ClickFix Phishing – Source:thehackernews.com https://ciso2ciso.com/castleloader-malware-infects-469-devices-using-fake-github-repos-and-clickfix-phishing-sourcethehackernews-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #TheHackerNews #CastleLoader