CASTLELOADER

Malware type
loader
Family
Malware family
Last IoC activity
2026-07-21 04:39:17
Profile updated
2026-07-07 13:17:50

Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications

Context

CastleLoader payloads are distributed as portable executables containing an embedded shellcode, which then invokes the main module of the loader that, in turn, connects to the C2 server in order to fetch and execute the next-stage malware.

Reports & references

  • recordedfuture.com — Graybravos Castleloader Activity Clusters Target Multiple Industries (report)
  • research.checkpoint.com — Iranian Mois Actors The Cyber Crime Connection (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Castleloader (report)
  • bitdefender.com — Lummastealer Second Life Castleloader (report)
  • blackpointcyber.com — Python Driven Castleloader Analysis (report)
  • blog.polyswarm.io — Castleloader (report)
  • medium.com — Castleloader Malware Overview A44B9Db666B8 (report)
  • cypro.se — Castleloader Malware Infects 469 Devices Using Fake Github Repos And Clickfix Phishing (report)
  • ibm.com — Dissecting Castlebot Maas Operation (report)
  • catalyst.prodaft.com — Overview (report)
  • any.run — Castleloader Malware Analysis (report)

External references