CASTLELOADER
- Malware type
- loader
- Family
- Malware family
- Last IoC activity
- 2026-07-21 04:39:17
- Profile updated
- 2026-07-07 13:17:50
Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications
Context
CastleLoader payloads are distributed as portable executables containing an embedded shellcode, which then invokes the main module of the loader that, in turn, connects to the C2 server in order to fetch and execute the next-stage malware.
Reports & references
- recordedfuture.com — Graybravos Castleloader Activity Clusters Target Multiple Industries (report)
- research.checkpoint.com — Iranian Mois Actors The Cyber Crime Connection (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Castleloader (report)
- bitdefender.com — Lummastealer Second Life Castleloader (report)
- blackpointcyber.com — Python Driven Castleloader Analysis (report)
- blog.polyswarm.io — Castleloader (report)
- medium.com — Castleloader Malware Overview A44B9Db666B8 (report)
- cypro.se — Castleloader Malware Infects 469 Devices Using Fake Github Repos And Clickfix Phishing (report)
- ibm.com — Dissecting Castlebot Maas Operation (report)
- catalyst.prodaft.com — Overview (report)
- any.run — Castleloader Malware Analysis (report)