logo

ClickFix Social Engineering Sparks Rise of CastleLoader Attacks

ID: 025049d0-50b8-5b38-8666-c3f6129e3be6

STIX ID: report--025049d0-50b8-5b38-8666-c3f6129e3be6

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2025-12-10

Date Updated: 2026-04-22

...
...

A newly observed CastleLoader campaign leverages ClickFix social-engineering prompts to get victims to run a command that launches a hidden conhost.exe to fetch a tar archive, unpack a Python interpreter in AppData, and execute compiled Python bytecode that reconstructs and runs CastleLoader shellcode entirely in memory. The chain replaces prior AutoIt droppers with a compact Python loader; uses PEB Walking, hashed DLL/API identifiers, and XOR decryption of staged payloads; and exhibits network markers (notably the GoogeBot user agent and a known staging path) consistent with prior CastleLoader activity. Blackpoint recommends user education, restricting Run dialog and scripting interpreters, monitoring LOLBin sequences, DNS tracking, and watching for Python binaries from atypical locations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.