NightshadeC2 (Windows)
Aliases: CastleRAT
- Malware type
- rat, keylogger, screen-capture, credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-21 04:33:09
- Profile updated
- 2026-07-07 13:17:48
Targeted industries: financial-services government-and-public-sector technology-and-telecommunications
Context
According to eSentire, NightshadeC2 demonstrates an extensive capability set, including: Reverse shell via Command Prompt/PowerShell; Download and execute DLL or EXE; Self-deletion; Remote control; Screen capture; Hidden web browsers; Keylogging; clipboard content capturing. Certain variants have been found with stealing capabilities that enable the extraction of browser passwords and cookies from victim systems for both Gecko and Chromium based browsers.
Detection coverage
- 1 YARA rules
Detection rules
- CAPE_Nightshadec2 (yara-rule)
Reports & references
- recordedfuture.com — Graybravos Castleloader Activity Clusters Target Multiple Industries (report)
- recordedfuture.com — From Castleloader To Castlerat Tag 150 Advances Operations (report)
- esentire.com — New Botnet Emerges From The Shadows Nightshadec2 (report)
- ibm.com — Dissecting Castlebot Maas Operation (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Nightshade C2 (report)
- blog.deception.pro — Castlerat Dec2025 Hok Ato (report)