Skip to content
CastleStealer Malware Enhances Capabilities with Remote Command Execution

CastleStealer Malware Enhances Capabilities with Remote Command Execution

First seen 9 Oct 2026, 12:39 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 13:34 UTC
  • •CastleStealer now includes remote command execution capabilities.
  • •The malware can bypass app-bound encryption in Chromium browsers.
  • •Exfiltration of stolen data occurs in small encrypted packets.

CastleStealer, a C# information-stealing malware first identified in April 2026, has evolved to include remote command execution and the ability to bypass app-bound encryption in Chromium-based browsers. Recent samples analyzed by Flashpoint show that it can now exfiltrate stolen data in small encrypted packets rather than a single large archive. The malware primarily targets credentials, cookies, and browsing history from browsers like Chrome and Firefox, as well as configuration files from applications like Steam, Discord, and Telegram. The malware employs sophisticated loaders, including OXLOADER, which utilize multiple self-decryption stages and anti-analysis techniques. Despite its advanced capabilities, Flashpoint notes that widespread adoption among threat actors has not yet been observed. The malware's operators continue to refine its delivery methods and payload functionalities, indicating a significant threat potential. Flashpoint has not confirmed any of CastleStealer at this time.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-04-01
CastleStealer first identified
CastleStealer was first publicly identified using ClickFix social engineering to deliver a Python script.
flashpoint.io
2026-10-09
CastleStealer capabilities expanded
New samples analyzed show enhanced features including remote command execution and bypassing browser encryption.
Gbhackers

More articles in this cluster (2)

Following this threat?

Track CastleLoader in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What data does CastleStealer target?
CastleStealer targets credentials, cookies, browsing history, and configuration files from various applications.
Is CastleStealer actively exploited?
There is currently no confirmed active exploitation of CastleStealer reported by Flashpoint.
What should organizations do to protect against CastleStealer?
Organizations should enhance their security measures, including monitoring for suspicious browser activity and educating users about social engineering tactics.