Threat reportMalwareTL-2026-3056

CastleStealer: Emerging .NET Infostealer Bypassing Chromium App-Bound Encryption via CastleLoader and OXLOADER

mediumACTIVE

CastleStealer (TL-2026-3056), also tracked as CASTLESTEALER, is a medium-severity malware campaign, first published 2026-10-08 and last reviewed 2026-10-09. It has no confirmed attribution, affects Microsoft Windows, maps to 28 MITRE ATT&CK techniques (T1005, T1027.007, T1027.009), and is covered by 9 detection rules and 52 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
28MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
52Indicators of compromise

Key facts for TL-2026-3056

Threat ID
TL-2026-3056
Also known as
CASTLESTEALER, OXLOADER, CastleLoader, BackgroundFix, REF8372
Severity
MEDIUM
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, cryptocurrency, consumer, gaming
Target regions
Global
Detection rules
9
Indicators of compromise
52
Updates
2026-10-09 · 2 updates · revalidated 2× · latest source

Malware and tooling in CastleStealer

Malware and tooling: CASTLELOADER, CastleStealer, OXLOADER, telegram

How CastleStealer works

CastleStealer is a .NET infostealer first identified in April 2026 that steals Chromium/Firefox credentials, cookies, extension and wallet data, Steam/Discord/Telegram files, and exfiltrates over small AES-encrypted raw TCP transmissions. Flashpoint reports newer samples bypass Chromium app-bound encryption through Chrome's IElevator COM interface and add basic remote shell functions. It is delivered by two documented chains: ClickFix lures leading to CastleLoader, and malvertising to fake Node.js installer sites leading to OXLOADER.

CastleStealer is a .NET information stealer first publicly identified in April 2026 and now documented by Huntress (April 2026 ClickFix/CastleLoader chain), Elastic Security Labs (June 2026 OXLOADER campaign, REF8372) and Flashpoint (8 October 2026). Flashpoint reports that newer samples use Chrome's IElevator COM interface to bypass Chromium app-bound encryption, which the earlier Huntress-analysed sample did not implement (it used DPAPI/CryptUnprotectData with AES). Flashpoint also describes basic remote shell functionality: an operator can send a shell command, supply a file for execution, or send a URL that the stealer downloads and executes.

Delivery chain 1 (April 2026, ClickFix / CastleLoader): Huntress documented a fake free image-background-removal site ("BackgroundFix") with a fake upload, progress bar and CAPTCHA step that places a command on the clipboard. The cmd /k command uses the finger client to query an attacker server (cheeshomireciple.com) and executes the returned line. A .plan payload then runs a batch stage that uses curl.exe to fetch a Python embeddable package (saved with a .pdf extension), tar.exe to extract it, and a renamed Python binary to run a downloader that decodes a ctypes shellcode loader. Shellcode stages (djb2 API hashing, RC4, ReplaceTextW hook execution, reflective PE loading with PEB rewriting) load CastleLoader, which talks HTTPS to C2 and dispatches tasks through 14 launch methods. Observed tasks delivered NetSupport RAT (persistence via a logon-triggered scheduled task) and CastleStealer, fileless as net40.bin injected via APC. CastleLoader is tracked by Recorded Future as GrayBravo (formerly TAG-150), a malware-as-a-service operation; Huntress/Elastic note the link to CastleStealer is distribution, not proven operator identity.

Delivery chain 2 (June 2026, malvertising / OXLOADER, Elastic REF8372): victims searching for 'lts version of node.js' were redirected through Google Ads (advertiser account removed 14 May 2026) via app.miloyannopoulos.com to the fake site node-js.prentiva99.info. A Storj-hosted batch script (BATPackageBuilderSetup.bat / BATPackageBulderSetup.bat) displays a bogus installer wizard while PowerShell downloads a Storj-hosted OXLOADER executable and launches it with -Verb RunAs, triggering a UAC prompt. OXLOADER uses control-flow flattening, opaque predicates, mixed Boolean-Arithmetic obfuscation, self-modifying decryption stubs and .reloc-section shellcode staging; it copies C:\Windows\System32\dui70.dll to PFHemkxVk.ocx, adds an RWX .xtext section and loads it (DLL side-loading/module stomping), then decrypts a DonutLoader shellcode that runs CastleStealer in memory via RunPE(). Anti-analysis checks include WNetAddConnection2W with a malformed resource, minimum 3 CPUs, 3 GB RAM, 20 Hz refresh rate, CIS GeoID exclusion and a Russian UI-language (0x419) check. Elastic assesses the operator is likely Russian-speaking and financially motivated.

Stealer behaviour: collects Chromium login data, cookies, history, web data, extension IDs, IndexedDB and extension storage; Firefox logins, cookies, history and form history; Steam config.vdf/loginusers.vdf/local.vdf; Discord and Telegram directories under APPDATA; files broadly, skipping some types and files containing 'backup' while prioritising names containing 'wallet'. It exits if ru-RU is among the installed MUI languages, sends a handshake with a build UUID and host information, and self-deletes with a ping-delay command (cmd.exe /C ping 1.0.0.1 & del "<path>") when finished. Exfiltration is raw TCP in small AES-encrypted transmissions (packet: 4-byte size, AES IV, encrypted data; AES-128-CBC described by Flashpoint), which may avoid large-transfer-spike detections. Huntress observed the earlier sample sending to 38.146.28.30:22989.

Flashpoint has not seen widespread actor adoption and names no actor for CastleStealer itself, hence MEDIUM severity. The stealer is high-impact for any victim: harvested session tokens and wallet data enable account takeover and cryptocurrency theft. No CVEs are involved.

MITRE ATT&CK techniques used in TL-2026-3056

Collection

T1005 Data from Local System; T1113 Screen Capture

Defense Evasion

T1027.007 Obfuscated Files or Information: Dynamic API Resolution; T1027.009 Obfuscated Files or Information: Embedded Payloads; T1027.013 Obfuscated Files or Information: Encrypted/Encoded File; T1036.005 Masquerading: Match Legitimate Resource Name or Location; T1055.012 Process Injection: Process Hollowing; T1070.004 Indicator Removal: File Deletion; T1497.001 Virtualization/Sandbox Evasion: System Checks; T1574.001 DLL; T1620 Reflective Code Loading

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1059.006 Command and Scripting Interpreter: Python; T1204.002 User Execution: Malicious File; T1204.004 User Execution: Malicious Copy and Paste; T1559.001 Inter-Process Communication: Component Object Model

Discovery

T1082 System Information Discovery; T1614.001 System Location Discovery: System Language Discovery

Command and Control

T1095 Non-Application Layer Protocol; T1105 Ingress Tool Transfer; T1573.001 Encrypted Channel: Symmetric Cryptography

Credential Access

T1539 Steal Web Session Cookie; T1555.003 Credentials from Password Stores: Credentials from Web Browsers

Privilege Escalation

T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control

Resource Development

T1583.008 Acquire Infrastructure: Malvertising; T1608.001 Stage Capabilities: Upload Malware

Affected products and versions in CastleStealer

  • Microsoft — Windows
    Vulnerable versions: Windows endpoints running Chromium-based browsers, Firefox, Steam, Discord or Telegram
  • Google — Chrome / Chromium-based browsers (app-bound encryption)
    Vulnerable versions: Credential stores of Chromium browsers on compromised hosts

Remediation for CastleStealer

Immediate actions

  • Hunt for and block the C2 IPs, domains and Storj URLs listed in the IOCs
  • Alert on cmd.exe using the finger client with for /f, and on curl.exe/tar.exe fetching and unpacking a Python embeddable package from a user context
  • Isolate hosts with a hit and rotate all browser-stored credentials, revoke session tokens and move wallet funds from affected hosts

Workarounds

  • Install developer tools such as Node.js only from official sites, not sponsored search results
  • Use application control to block unsigned executables launched from temp/download paths with RunAs prompts

Longer-term hardening

  • Restrict Win+R/clipboard paste execution for non-admin users and train users on ClickFix lures
  • Block or monitor finger.exe outbound and egress to storjshare.io from workstations where not needed
  • Enforce passkeys/hardware-bound MFA and short session lifetimes so stolen cookies have limited value
  • Deploy EDR rules for module stomping from a copied library, CLR loaded from suspicious memory and RunPE-style hollowing of powershell.exe

Timeline of CastleStealer

  • Recorded Future reports CastleLoader activity clusters (GrayBravo/TAG-150) active since at least March 2025, delivering stealers and RATs via ClickFix and phishing.
  • CastleStealer first publicly identified, delivered via ClickFix (BackgroundFix lure) and a Python script that ran CastleLoader (Flashpoint/Huntress; April 2026, day not stated).
  • Elastic identifies a second OXLOADER variant masquerading as a Node.js binary (node-v24.15.0-x64-86.exe).
  • Google removed the advertiser account and campaigns used in the fake Node.js malvertising campaign (Elastic).
  • Second delivery chain observed in June 2026: malicious ads lead to fake Node.js installer sites, a Storj-hosted batch script and OXLOADER delivering CastleStealer (Flashpoint; day not stated).
  • Arctic Wolf records upload of the PowerShell stager for the Urutyka CastleLoader campaign (VNC viewer plus NetSupport RAT).
  • Elastic Security Labs publishes OXLOADER analysis (campaign REF8372) linking it to CASTLESTEALER.
  • The Hacker News covers the OXLOADER / CastleStealer malvertising campaign.
  • Multiple finger-protocol delivery domains identified; avivtech.org observed pulling py-Castle payloads on 2026-06-23/24.
  • Arctic Wolf publishes the Urutyka, Garrigin and Noidret CastleLoader campaign clusters and the NeedleStealer connection.
  • Flashpoint reports newer CastleStealer samples bypassing Chromium app-bound encryption via the IElevator COM interface and adding basic remote shell functions.
  • Cyber Security News and other outlets report the new CastleStealer capabilities (ABE bypass, remote shell); coverage publishes no hashes or C2 indicators.

Update history for TL-2026-3056

Sources cited for CastleStealer

Detection coverage for TL-2026-3056

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3056 across Splunk SPL, Microsoft KQL and Sigma, covering 52 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
52 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats