CastleBot Malware-as-a-Service Deploys Range of Payloads Linked to Ransomware Attacks
ID: 1fa00bcf-2c59-5a75-ab0b-3f60e9840432
STIX ID: report--1fa00bcf-2c59-5a75-ab0b-3f60e9840432
Feed Name: cybersecurityNews.com
CastleBot is a MaaS discovered in early 2025 that uses trojanized installers (via SEO-poisoned sites, fake GitHub repos and ClickFix) to deliver a modular three-stage payload (stager/downloader, in-memory PE loader, core backdoor). The framework supports dynamic C2 tasking and victim profiling, has been linked to NetSupport/WarmCookie backdoors and ransomware activity, and employs advanced evasion (runtime API hashing, in-memory mapping and manipulation of loader/PE structures) with observable IoCs and a noted activity surge starting May 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
