logo

Intelligence Insights: July 2026

ID: 8a063319-82b2-5798-9702-be0d63764617

STIX ID: report--8a063319-82b2-5798-9702-be0d63764617

Feed Name: Red Canary

Threat Score
75/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: The Red Canary Team

...
...

CastleLoader is an active malware loader (observed since early 2025) deployed in paste-and-run and job-platform impersonation campaigns that lure victims to fake background-removal sites and typosquatted job pages distributed via Google Ads; the infection chain uses caret-obfuscated commands, BYOI portable Python interpreters renamed and executed, a triple-encoded/zlib-compressed Python-based shellcode loader that fetches an RC4-encrypted CastleLoader binary, which is injected into python.exe and connects to C2 for further payloads. The loader supports many launch methods, includes anti-analysis checks (VM detection via CPUID), can capture screenshots, and provides multiple detection opportunities (for example caret obfuscation and specific domains/command patterns).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.