New CastleLoader Variant Linked to 469 Infections Across Critical Sectors
ID: 667891a9-dec9-5d64-a907-6a1408242844
STIX ID: report--667891a9-dec9-5d64-a907-6a1408242844
Feed Name: HackRead
Threat Score
CastleLoader is a stealthy, fileless loader observed since 2025 that uses social-engineering (“ClickFix” fake update/pop-up) and Inno Setup/AutoIt to infect systems, performs process hollowing of jsc.exe, calls back to C2 94.159.113.32, and can drop info-stealers and RATs; researchers report at least 469 compromised devices including US government and European critical infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
