logo

LummaStealer infections surge after CastleLoader malware campaigns

ID: 1f438599-9a66-5c47-b0e3-e81cc6e2d002

STIX ID: report--1f438599-9a66-5c47-b0e3-e81cc6e2d002

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-02-11

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Bitdefender reports a significant resurgence of the LummaStealer infostealer between December 2025 and January 2026, now widely delivered via the CastleLoader malware loader and ClickFix social-engineering campaigns; CastleLoader is a heavily obfuscated AutoIT/Python in-memory loader that performs sandbox checks, uses multiple persistence techniques, intentionally triggers a failed DNS lookup (a detectable artifact), and fetches and executes LummaStealer and other infostealers distributed through trojanized installers, pirated software, and fake verification pages that trick users into running malicious PowerShell commands.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.