NightshadeC2 (Windows)

Aliases: CastleRAT

Malware type
rat, keylogger, screen-capture, credential-stealer
Family
Malware family
Last IoC activity
2026-07-21 04:33:09
Profile updated
2026-07-07 13:17:48

Targeted industries: financial-services government-and-public-sector technology-and-telecommunications

Context

According to eSentire, NightshadeC2 demonstrates an extensive capability set, including: Reverse shell via Command Prompt/PowerShell; Download and execute DLL or EXE; Self-deletion; Remote control; Screen capture; Hidden web browsers; Keylogging; clipboard content capturing. Certain variants have been found with stealing capabilities that enable the extraction of browser passwords and cookies from victim systems for both Gecko and Chromium based browsers.

Detection coverage

  • 1 YARA rules

Detection rules

  • CAPE_Nightshadec2 (yara-rule)

Reports & references

  • recordedfuture.com — Graybravos Castleloader Activity Clusters Target Multiple Industries (report)
  • recordedfuture.com — From Castleloader To Castlerat Tag 150 Advances Operations (report)
  • esentire.com — New Botnet Emerges From The Shadows Nightshadec2 (report)
  • ibm.com — Dissecting Castlebot Maas Operation (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Nightshade C2 (report)
  • blog.deception.pro — Castlerat Dec2025 Hok Ato (report)

External references