Intelligence Insights: July 2026
ID: 8a063319-82b2-5798-9702-be0d63764617
STIX ID: report--8a063319-82b2-5798-9702-be0d63764617
Feed Name: Red Canary
CastleLoader is an active malware loader (observed since early 2025) deployed in paste-and-run and job-platform impersonation campaigns that lure victims to fake background-removal sites and typosquatted job pages distributed via Google Ads; the infection chain uses caret-obfuscated commands, BYOI portable Python interpreters renamed and executed, a triple-encoded/zlib-compressed Python-based shellcode loader that fetches an RC4-encrypted CastleLoader binary, which is injected into python.exe and connects to C2 for further payloads. The loader supports many launch methods, includes anti-analysis checks (VM detection via CPUID), can capture screenshots, and provides multiple detection opportunities (for example caret obfuscation and specific domains/command patterns).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
