logo

Hackers Using CastleRAT Malware to Attack Windows Systems and Gain Remote Access

ID: 4ccec6c9-b1cd-54db-b1cf-bd10cfb0abdf

STIX ID: report--4ccec6c9-b1cd-54db-b1cf-bd10cfb0abdf

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-05

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

CastleRAT is a recently observed Remote Access Trojan (first seen March 2025) offered in Python and compiled C variants; the C build implements advanced features including keystroke logging, screen capture, persistence, and RC4-encrypted command-and-control. Notably, it harvests clipboard contents and exfiltrates data by simulating paste actions to blend with normal user activity; the report maps techniques to MITRE ATT&CK and provides detection guidance such as monitoring for RC4-encrypted traffic, one-line PowerShell downloads, and unexpected binaries in user folders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.