Hackers Using CastleRAT Malware to Attack Windows Systems and Gain Remote Access
ID: 4ccec6c9-b1cd-54db-b1cf-bd10cfb0abdf
STIX ID: report--4ccec6c9-b1cd-54db-b1cf-bd10cfb0abdf
Feed Name: cybersecurityNews.com
CastleRAT is a recently observed Remote Access Trojan (first seen March 2025) offered in Python and compiled C variants; the C build implements advanced features including keystroke logging, screen capture, persistence, and RC4-encrypted command-and-control. Notably, it harvests clipboard contents and exfiltrates data by simulating paste actions to blend with normal user activity; the report maps techniques to MITRE ATT&CK and provides detection guidance such as monitoring for RC4-encrypted traffic, one-line PowerShell downloads, and unexpected binaries in user folders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
