logo

CastleBot Malware-as-a-Service Deploys Range of Payloads Linked to Ransomware Attacks

ID: 1fa00bcf-2c59-5a75-ab0b-3f60e9840432

STIX ID: report--1fa00bcf-2c59-5a75-ab0b-3f60e9840432

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-08-08

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

CastleBot is a MaaS discovered in early 2025 that uses trojanized installers (via SEO-poisoned sites, fake GitHub repos and ClickFix) to deliver a modular three-stage payload (stager/downloader, in-memory PE loader, core backdoor). The framework supports dynamic C2 tasking and victim profiling, has been linked to NetSupport/WarmCookie backdoors and ransomware activity, and employs advanced evasion (runtime API hashing, in-memory mapping and manipulation of loader/PE structures) with observable IoCs and a noted activity surge starting May 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.