Stealthy CastleLoader Malware Attacking US Government Agencies and Critical Infrastructure
ID: d82ed05d-10cb-5aae-bddc-e8419f0e6737
STIX ID: report--d82ed05d-10cb-5aae-bddc-e8419f0e6737
Feed Name: cybersecurityNews.com
CastleLoader is a stealthy, multi-stage malware loader observed in early 2025 that has been used to compromise ~460 organizations — including U.S. government agencies and critical infrastructure — by delivering secondary payloads (info-stealers and RATs) directly into memory. The campaign uses social-engineering lures (a 'ClickFix' fake-update vector) and an Inno Setup/AutoIt installer to launch a suspended jsc.exe process, then performs advanced process hollowing and memory injection to evade disk- and signature-based detection, enabling persistent, hard-to-detect footholds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
