ThreatCluster

CastleLoader Campaign Uses NeedleStealer to Target Crypto Users

First seen 29 Jul 2026, 02:49 UTC GbhackersCybersecuritynews 72% similarity 67

Article Content

Browse articles
ThreatCluster

The CastleLoader malware campaign has evolved, deploying the NeedleStealer framework to steal cryptocurrency wallet seed phrases and hijack browser sessions. This operation targets Windows devices through fake software installers and deceptive prompts. Recent findings from Huntress and LevelBlue confirm that CastleLoader remains a primary delivery mechanism for multi-stage intrusions. Attackers use convincing fake wallet screens and browser extensions to harvest sensitive information. The scope of the attack is significant, affecting numerous users who interact with cryptocurrency applications. Current reports indicate that the campaign is ongoing, with new tools developed in Rust and Golang being utilized. Security professionals are advised to remain vigilant against these tactics.

Key Points: • CastleLoader malware now deploys NeedleStealer to steal crypto wallet seeds. • Attackers use fake wallet screens and browser extensions to harvest sensitive data. • The campaign primarily targets Windows devices through deceptive software installers.

ThreatCluster AI How this analysis works

Timeline

2026-07-28
CastleLoader campaign evolves with NeedleStealer
New findings reveal the use of NeedleStealer for stealing crypto wallet seeds and browser sessions, confirming ongoing threats.
Gbhackers
2026-07-28
Fake crypto wallet screens identified
Criminals are using convincing fake wallet screens to steal recovery phrases and login data linked to the CastleLoader campaign.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story