# CastleStealer: Emerging .NET Infostealer Bypassing Chromium App-Bound Encryption via CastleLoader and OXLOADER

> CastleStealer is a .NET infostealer first identified in April 2026 that steals Chromium/Firefox credentials, cookies, extension and wallet data, Steam/Discord/Telegram files, and exfiltrates over small AES-encrypted raw TCP transmissions. Flashpoint reports newer samples bypass Chromium app-bound encryption through Chrome's IElevator COM interface and add basic remote shell functions. It is delivered by two documented chains: ClickFix lures leading to CastleLoader, and malvertising to fake Node.js installer sites leading to OXLOADER.

- **Published:** 2026-10-08T00:00:00Z
- **Last reviewed:** 2026-10-09T22:13:10.843Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3056
- **ID:** TL-2026-3056
- **Severity:** MEDIUM
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 52 (full data via the Threadlinqs MCP server — Purple tier)

## Description

CastleStealer is a .NET information stealer first publicly identified in April 2026 and now documented by Huntress (April 2026 ClickFix/CastleLoader chain), Elastic Security Labs (June 2026 OXLOADER campaign, REF8372) and Flashpoint (8 October 2026). Flashpoint reports that newer samples use Chrome's IElevator COM interface to bypass Chromium app-bound encryption, which the earlier Huntress-analysed sample did not implement (it used DPAPI/CryptUnprotectData with AES). Flashpoint also describes basic remote shell functionality: an operator can send a shell command, supply a file for execution, or send a URL that the stealer downloads and executes.

Delivery chain 1 (April 2026, ClickFix / CastleLoader): Huntress documented a fake free image-background-removal site ("BackgroundFix") with a fake upload, progress bar and CAPTCHA step that places a command on the clipboard. The cmd /k command uses the finger client to query an attacker server (cheeshomireciple.com) and executes the returned line. A .plan payload then runs a batch stage that uses curl.exe to fetch a Python embeddable package (saved with a .pdf extension), tar.exe to extract it, and a renamed Python binary to run a downloader that decodes a ctypes shellcode loader. Shellcode stages (djb2 API hashing, RC4, ReplaceTextW hook execution, reflective PE loading with PEB rewriting) load CastleLoader, which talks HTTPS to C2 and dispatches tasks through 14 launch methods. Observed tasks delivered NetSupport RAT (persistence via a logon-triggered scheduled task) and CastleStealer, fileless as net40.bin injected via APC. CastleLoader is tracked by Recorded Future as GrayBravo (formerly TAG-150), a malware-as-a-service operation; Huntress/Elastic note the link to CastleStealer is distribution, not proven operator identity.

Delivery chain 2 (June 2026, malvertising / OXLOADER, Elastic REF8372): victims searching for 'lts version of node.js' were redirected through Google Ads (advertiser account removed 14 May 2026) via app.miloyannopoulos.com to the fake site node-js.prentiva99.info. A Storj-hosted batch script (BATPackageBuilderSetup.bat / BATPackageBulderSetup.bat) displays a bogus installer wizard while PowerShell downloads a Storj-hosted OXLOADER executable and launches it with -Verb RunAs, triggering a UAC prompt. OXLOADER uses control-flow flattening, opaque predicates, mixed Boolean-Arithmetic obfuscation, self-modifying decryption stubs and .reloc-section shellcode staging; it copies C:\Windows\System32\dui70.dll to PFHemkxVk.ocx, adds an RWX .xtext section and loads it (DLL side-loading/module stomping), then decrypts a DonutLoader shellcode that runs CastleStealer in memory via RunPE(). Anti-analysis checks include WNetAddConnection2W with a malformed resource, minimum 3 CPUs, 3 GB RAM, 20 Hz refresh rate, CIS GeoID exclusion and a Russian UI-language (0x419) check. Elastic assesses the operator is likely Russian-speaking and financially motivated.

Stealer behaviour: collects Chromium login data, cookies, history, web data, extension IDs, IndexedDB and extension storage; Firefox logins, cookies, history and form history; Steam config.vdf/loginusers.vdf/local.vdf; Discord and Telegram directories under APPDATA; files broadly, skipping some types and files containing 'backup' while prioritising names containing 'wallet'. It exits if ru-RU is among the installed MUI languages, sends a handshake with a build UUID and host information, and self-deletes with a ping-delay command (cmd.exe /C ping 1.0.0.1 & del "<path>") when finished. Exfiltration is raw TCP in small AES-encrypted transmissions (packet: 4-byte size, AES IV, encrypted data; AES-128-CBC described by Flashpoint), which may avoid large-transfer-spike detections. Huntress observed the earlier sample sending to 38.146.28.30:22989.

Flashpoint has not seen widespread actor adoption and names no actor for CastleStealer itself, hence MEDIUM severity. The stealer is high-impact for any victim: harvested session tokens and wallet data enable account takeover and cryptocurrency theft. No CVEs are involved.

## MITRE ATT&CK

- T1583.008 Acquire Infrastructure: Malvertising
- T1608.001 Stage Capabilities: Upload Malware
- T1204.004 User Execution: Malicious Copy and Paste
- T1204.002 User Execution: Malicious File
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1059.006 Command and Scripting Interpreter: Python
- T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control
- T1574.001 DLL
- T1027.009 Obfuscated Files or Information: Embedded Payloads
- T1036.005 Masquerading: Match Legitimate Resource Name or Location
- T1497.001 Virtualization/Sandbox Evasion: System Checks
- T1620 Reflective Code Loading
- T1070.004 Indicator Removal: File Deletion
- T1555.003 Credentials from Password Stores: Credentials from Web Browsers
- T1539 Steal Web Session Cookie
- T1614.001 System Location Discovery: System Language Discovery
- T1005 Data from Local System
- T1095 Non-Application Layer Protocol
- T1573.001 Encrypted Channel: Symmetric Cryptography
- T1055.012 Process Injection: Process Hollowing
- T1027.007 Obfuscated Files or Information: Dynamic API Resolution
- T1027.013 Obfuscated Files or Information: Encrypted/Encoded File
- T1082 System Information Discovery
- T1113 Screen Capture
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel
- T1559.001 Inter-Process Communication: Component Object Model

## Sources

- [CastleStealer: An Emerging Infostealer Growing More Sophisticated (Flashpoint)](https://flashpoint.io/blog/castlestealer-an-emerging-infostealer-growing-more-sophisticated/)
- [OXLOADER malware loader and infostealer (Elastic Security Labs)](https://www.elastic.co/security-labs/oxloader-malware-loader-infostealer)
- [New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer (The Hacker News)](https://thehackernews.com/2026/06/new-oxloader-loader-uses-malicious.html)
- [ClickFix, CastleLoader and BackgroundFix (Huntress)](https://www.huntress.com/blog/clickfix-castleloader-backgroundfix)
- [Four Threat Clusters Using CastleLoader (The Hacker News)](https://thehackernews.com/2025/12/four-threat-clusters-using-castleloader.html)
- [GrayBravo's CastleLoader Activity Clusters Target Multiple Industries (Recorded Future Insikt Group)](https://www.recordedfuture.com/research/graybravos-castleloader-activity-clusters-target-multiple-industries)
- [Python-driven CastleLoader analysis (Blackpoint)](https://blackpointcyber.com/blog/python-driven-castleloader-analysis/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3056
