malware
Published 2026-10-08
Verified 2026-10-10

CastleStealer grows up: Flashpoint says the C# infostealer now beats Chrome's App-Bound Encryption, takes remote shell commands and extra payloads, and leaks data in small AES-encrypted TCP bursts to dodge network alerts

Flashpoint published an analysis on 8 October 2026 of CastleStealer, a C# information stealer first seen in April 2026 in a ClickFix campaign that ran a Python script to launch a loader called CastleLoader. By June it was spreading through malicious search ads for Node.js that led to fake installer sites, where a batch file pulled down an in-house loader called OXLOADER that decrypts itself in several rounds, hides its API calls, checks for sandboxes and runs in memory. Newer samples skip Russian-language systems, send a handshake with a build ID to their command server, then collect Chromium browser logins, cookies, history, form data and extension storage. They now get past Chrome's App-Bound Encryption by abusing the browser's IElevator COM interface, a trick other modern stealers also use. A basic remote shell lets an operator run commands, push a file to run or have the malware download another payload, so an infection does not end once passwords are taken. Stolen data leaves in small AES-encrypted chunks over raw TCP rather than one big archive, which Flashpoint says may avoid alerts for large transfers; the malware then deletes itself. Flashpoint has not yet seen wide uptake by criminals. Primary: Flashpoint; wire: Cyber Security News.

Product
Windows endpoints — Chromium-based browsers (logins, cookies, extension data)
Versions
n/a — malware family (newer samples add App-Bound Encryption bypass and remote shell)
Exploited in Australia?
unknown
Patch to
Teach staff to download developer tools such as Node.js only from the official site, not search ads, and block ClickFix-style 'paste this command' prompts by restricting the Run dialog and PowerShell for standard users. Alert on processes other than the browser using Chrome's elevation service, and on a suspected infection revoke browser sessions and tokens as well as resetting passwords.

Primary: Flashpoint — CastleStealer: an emerging infostealer growing more sophisticated (8 Oct 2026) · Cyber Security News — CastleStealer uses browser protection bypass and remote shell (9 Oct 2026)

tech identity network