flashpoint.io CastleStealer Malware Enhances Capabilities with Remote Command Execution
Article Content
- •CastleStealer now includes remote command execution capabilities.
- •The malware can bypass app-bound encryption in Chromium browsers.
- •Exfiltration of stolen data occurs in small encrypted packets.
CastleStealer, a C# information-stealing malware first identified in April 2026, has evolved to include remote command execution and the ability to bypass app-bound encryption in Chromium-based browsers. Recent samples analyzed by Flashpoint show that it can now exfiltrate stolen data in small encrypted packets rather than a single large archive. The malware primarily targets credentials, cookies, and browsing history from browsers like Chrome and Firefox, as well as configuration files from applications like Steam, Discord, and Telegram. The malware employs sophisticated loaders, including OXLOADER, which utilize multiple self-decryption stages and anti-analysis techniques. Despite its advanced capabilities, Flashpoint notes that widespread adoption among threat actors has not yet been observed. The malware's operators continue to refine its delivery methods and payload functionalities, indicating a significant threat potential. Flashpoint has not confirmed any of CastleStealer at this time.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CastleLoader in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What data does CastleStealer target?
Is CastleStealer actively exploited?
What should organizations do to protect against CastleStealer?
Continue Reading
SloppyRAT: New Remote Access Trojan Fuels Ransomware Operations In June 2026, Zscaler ThreatLabz identified SloppyRAT, a new remote access trojan (RAT) used in ransomware attacks. Delivered through a multi-stage ClickFix infection chain, SloppyRAT employs advanced evasion techniques, including encrypted code and indirect Windows system calls. The malware allows attackers to…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…