CastleStealer grows up: Flashpoint says the C# infostealer now beats Chrome's App-Bound Encryption, takes remote shell commands and extra payloads, and leaks data in small AES-encrypted TCP bursts to dodge network alerts
Flashpoint published an analysis on 8 October 2026 of CastleStealer, a C# information stealer first seen in April 2026 in a ClickFix campaign that ran a Python script to launch a loader called CastleLoader. By June it was spreading through malicious search ads for Node.js that led to fake installer sites, where a batch file pulled down an in-house loader called OXLOADER that decrypts itself in several rounds, hides its API calls, checks for sandboxes and runs in memory. Newer samples skip Russian-language systems, send a handshake with a build ID to their command server, then collect Chromium browser logins, cookies, history, form data and extension storage. They now get past Chrome's App-Bound Encryption by abusing the browser's IElevator COM interface, a trick other modern stealers also use. A basic remote shell lets an operator run commands, push a file to run or have the malware download another payload, so an infection does not end once passwords are taken. Stolen data leaves in small AES-encrypted chunks over raw TCP rather than one big archive, which Flashpoint says may avoid alerts for large transfers; the malware then deletes itself. Flashpoint has not yet seen wide uptake by criminals. Primary: Flashpoint; wire: Cyber Security News.
- Product
- Windows endpoints — Chromium-based browsers (logins, cookies, extension data)
- Versions
- n/a — malware family (newer samples add App-Bound Encryption bypass and remote shell)
- Exploited in Australia?
- unknown
- Patch to
- Teach staff to download developer tools such as Node.js only from the official site, not search ads, and block ClickFix-style 'paste this command' prompts by restricting the Run dialog and PowerShell for standard users. Alert on processes other than the browser using Chrome's elevation service, and on a suspected infection revoke browser sessions and tokens as well as resetting passwords.
Primary: Flashpoint — CastleStealer: an emerging infostealer growing more sophisticated (8 Oct 2026) · Cyber Security News — CastleStealer uses browser protection bypass and remote shell (9 Oct 2026)
