logo

Stealthy CastleLoader Malware Attacking US Government Agencies and Critical Infrastructure

ID: d82ed05d-10cb-5aae-bddc-e8419f0e6737

STIX ID: report--d82ed05d-10cb-5aae-bddc-e8419f0e6737

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-01-14

Date Updated: 2026-04-21

Author: Balaji N

...
...

CastleLoader is a stealthy, multi-stage malware loader observed in early 2025 that has been used to compromise ~460 organizations — including U.S. government agencies and critical infrastructure — by delivering secondary payloads (info-stealers and RATs) directly into memory. The campaign uses social-engineering lures (a 'ClickFix' fake-update vector) and an Inno Setup/AutoIt installer to launch a suspended jsc.exe process, then performs advanced process hollowing and memory injection to evade disk- and signature-based detection, enabling persistent, hard-to-detect footholds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.