logo

Shell to pay: Crims invade your PC with CastleRAT malware, now in C and Python

ID: 4700625f-3dd7-5221-9e66-613a52e90906

STIX ID: report--4700625f-3dd7-5221-9e66-613a52e90906

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2025-09-05

Date Updated: 2026-04-26

Author: Iain Thomson

...
...

Recorded Future and related reporting describe TAG-150's CastleRAT malware — available in Python and C variants — spread via ClickFix social-engineering that tricks users into pasting malicious commands. The C build provides info-stealing capabilities (keystroke capture, screenshots, persistence) while the Python build prioritizes stealth; the group operates as a malware-as-a-service provider, uses encrypted Tox C2 and cloud hosting, and has demonstrated measurable success in persuading victims to self-install malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.