#castleloader
A surge in LummaStealer infections has been observed, driven by social engineering campaigns leveraging the ClickFix technique to deliver the CastleLoader malware.
LummaStealer infections surge after CastleLoader malware campaigns
A surge in LummaStealer infections has been observed, driven by social engineering campaigns leveraging the ClickFix technique to deliver the CastleLoader malware.
www.bleepingcomputer.com
February 11, 2026 at 5:02 PM
⚠️ CastleLoader expands with NeedleStealer payloads

Researchers linked new campaigns to crypto wallet spoofing and malicious browser extensions.

🔗 read more: securityonline.info/castleloader...

#ransomNews #cybersecurity
August 4, 2026 at 7:37 AM
CastleLoader malware, known for Clickfix related attack, has been upgraded with a stealthy Python loader that helps it slip past security defenses.

Read: hackread.com/castleloader...

#CyberSecurity #Malware #InfoSec #CastleLoader #ClickFix
CastleLoader Malware Now Uses Python Loader to Bypass Security
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
December 11, 2025 at 9:37 AM
Recorded Future’s Insikt Group uncovered four GrayBravo activity clusters. TAG-160 impersonates logistics firms, while TAG-161 impersonates Booking.com, employing ClickFix to deliver CastleLoader and Matanbuchus. www.recordedfuture.com/research/gra...
December 9, 2025 at 11:25 AM
📢⚠️ A new CastleLoader variant linked to at least 469 infections, hitting US government agencies and critical sectors across Europe.

Read: hackread.com/castleloader...

#CyberSecurity #Malware #CastleLoader #USGov #Europe
New CastleLoader Variant Linked to 469 Infections Across Critical Sectors
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
January 15, 2026 at 1:09 PM
LummaStealer infections surge after CastleLoader malware campaigns
LummaStealer infections surge after CastleLoader malware campaigns
A surge in LummaStealer infections has been observed, driven by social engineering campaigns leveraging the ClickFix technique to deliver the CastleLoader malware.
www.bleepingcomputer.com
February 11, 2026 at 5:25 PM
Another top-tier malware analysis writeup. This is a soup-to-nuts breakdown of CastleLoader, with clear explanations at every step.
CastleLoader Malware Analysis: Full Execution Breakdown 
Read full-cycle technical analysis of CastleLoader malware, covering its entire multi-stage execution by ANY.RUN.
any.run
January 15, 2026 at 9:54 PM
1/ @whoisnt.bsky.social, Marius, and I just published a report on #GrayBravo (formerly TAG-150), a highly adaptive, sophisticated threat actor that we first identified in Sept 2025. It uses a multi-layered infrastructure and responds quickly to exposure: www.recordedfuture.com/research/gra...
GrayBravo’s CastleLoader Activity Clusters Target Multiple Industries
www.recordedfuture.com
December 9, 2025 at 8:24 AM
10/ Bottom line: GrayBravo is expanding, diversifying, and professionalizing. Check out the full report with more details and IOCs: www.recordedfuture.com/research/gra...
GrayBravo’s CastleLoader Activity Clusters Target Multiple Industries
www.recordedfuture.com
December 9, 2025 at 8:24 AM
ANY.RUN looks into CastleLoader, a stealthy malware loader used as the first stage in attacks against government entities & multiple industries. CastleLoader delivers information stealers & RATs, enabling credential theft and persistent access. any.run/cybersecurit...
January 14, 2026 at 12:31 PM
CastleLoader in the wild! Four distinct activity clusters, sector-specific targeting of logistics, and high-end tooling like Matanbuchus and CastleRAT.
1/ @whoisnt.bsky.social, Marius, and I just published a report on #GrayBravo (formerly TAG-150), a highly adaptive, sophisticated threat actor that we first identified in Sept 2025. It uses a multi-layered infrastructure and responds quickly to exposure: www.recordedfuture.com/research/gra...
GrayBravo’s CastleLoader Activity Clusters Target Multiple Industries
www.recordedfuture.com
December 9, 2025 at 3:43 PM
CastleLoader tricks you into pasting your own malware, then hides inside a Python interpreter to inject it. https://intel.threadlinqs.com/threat/TL-2026-2589 #ThreatIntel #CASTLELOADER #NightshadeC2 #NetSupportManager
September 20, 2026 at 8:43 PM
9/ Historical CastleLoader panel analysis also surfaced links to an online persona, “Sparja”, active on Exploit Forums. While attribution remains cautious, the alias’s distinctiveness and activity patterns suggest potential ties to GrayBravo operations.
December 9, 2025 at 8:24 AM
-Firefox 147 is out
-Apple picks Gemini for Siri's AI
-Patch Tuesday is out
-SpyX stalkerware traced back to China
-Stormous ransomware "alliance" crumbles
-Malware reports on VoidLink, CastleLoader, AsyncRAT
-APT reports on UAC-0190, Contagious Interview
-ConnectPOS had a credential leak
January 14, 2026 at 9:54 AM
A significant amount of #CastleLoader C2 infrastructure identified by @julianferdinand.bsky.social was tied to #ThreatActivityEnabler 🇬🇧 FEMO IT SOLUTIONS #AS214351 utilising 🇩🇪 aurologic GmbH #AS30823 as their sole upstream provider. One to watch out for!
2/ TAG-150 is Insikt Group’s designation for the actor likely behind the malware families #CastleLoader, #CastleBot, and most recently #CastleRAT, a RAT documented here for the first time.
September 4, 2025 at 3:17 PM
7/ Another cluster, we track as TAG-161, impersonates Booking[.]com. This group also relies on ClickFix for CastleLoader delivery and deploys advanced payloads, including Matanbuchus.
December 9, 2025 at 8:24 AM
Insikt Group identifies a new threat actor, TAG-150, active since at least March 2025. Its multi-layered infrastructure is used to deploy likely self-developed malware families, including CastleLoader, CastleBot, and the newly documented CastleRAT. www.recordedfuture.com/research/fro...
September 8, 2025 at 8:33 AM
1/ Today @whoisnt.bsky.social, Marius, and I release a report on a new threat actor, #TAG-150, active since at least March 2025, which stands out for its rapid development, sophistication, responsiveness to reporting, and a large, evolving infrastructure: www.recordedfuture.com/research/fro...
From CastleLoader to CastleRAT: TAG-150 Advances Operations with Multi-Tiered Infrastructure
Insikt Group reveals TAG-150’s multi-tiered infrastructure and CastleRAT malware—an advanced threat actor evolving rapidly with stealth and scale.
www.recordedfuture.com
September 4, 2025 at 3:05 PM
FUD #CastleLoader being distributed via malvertizing.
785ba9c42deca8cfc69f1aafb371802782d01bc8156a67c5c0d412c5fb3b4e33

C2: astroflightvision[.]com

The signer, "Soft Insanity Oy" led us to find other FUD malware from November.
1/3
May 4, 2026 at 4:47 PM
2/ Our latest analysis uncovered four distinct activity clusters within GrayBravo’s ecosystem, all leveraging the group’s #CastleLoader malware. Each cluster uses different tactics, techniques, and targets, reinforcing the assessment that GrayBravo runs a #MaaS model.
December 9, 2025 at 8:24 AM
6/ Similar dynamics were observed in the loader and dropper landscape, where new malware families continued to emerge. One example is CastleLoader, attributed to GrayBravo, reinforcing the constant evolution of initial access tooling.
March 19, 2026 at 2:46 PM
3/ One cluster, we track as TAG-160, impersonates global logistics firms. Their campaigns use phishing lures and the #ClickFix technique to deliver CastleLoader. They also spoof legitimate logistics emails and abuse freight-matching platforms to reach victims.
December 9, 2025 at 8:24 AM
GrayBravo's CastleLoader ecosystem includes four clusters; TAG-160 impersonates logistics and abuses freight-matching platforms with ClickFix, TAG-161 impersonates Booking.com delivering CastleLoader and Matanbuchus. #GrayBravo #CastleLoader #ClickFix https://bit.ly/4p49yc0
December 13, 2025 at 7:19 PM