logo

New CastleLoader Variant Linked to 469 Infections Across Critical Sectors

ID: 667891a9-dec9-5d64-a907-6a1408242844

STIX ID: report--667891a9-dec9-5d64-a907-6a1408242844

Feed Name: HackRead

Threat Score
78/100

Date Published: 2026-01-15

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

CastleLoader is a stealthy, fileless loader observed since 2025 that uses social-engineering (“ClickFix” fake update/pop-up) and Inno Setup/AutoIt to infect systems, performs process hollowing of jsc.exe, calls back to C2 94.159.113.32, and can drop info-stealers and RATs; researchers report at least 469 compromised devices including US government and European critical infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.