Skip to content
ThreatCluster

CastleLoader Campaign Uses NeedleStealer to Target Crypto Users

First seen 29 Jul 2026, 02:49 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 30, 2026 at 01:53 UTC
  • CastleLoader malware now deploys NeedleStealer to steal crypto wallet seeds.
  • Attackers use fake wallet screens and browser extensions to harvest sensitive data.
  • The campaign primarily targets Windows devices through deceptive software installers.

The CastleLoader malware campaign has evolved, deploying the NeedleStealer framework to steal cryptocurrency wallet seed phrases and hijack browser sessions. This operation targets Windows devices through fake software installers and deceptive prompts. Recent findings from Huntress and LevelBlue confirm that CastleLoader remains a primary delivery mechanism for multi-stage intrusions. Attackers use convincing fake wallet screens and browser extensions to harvest sensitive information. The scope of the attack is significant, affecting numerous users who interact with cryptocurrency applications. Current reports indicate that the campaign is ongoing, with new tools developed in Rust and Golang being utilized. Security professionals are advised to remain vigilant against these tactics.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 54d ago How this analysis works

Timeline

2026-07-28
CastleLoader campaign evolves with NeedleStealer
New findings reveal the use of NeedleStealer for stealing crypto wallet seeds and browser sessions, confirming ongoing threats.
Gbhackers
2026-07-28
Fake crypto wallet screens identified
Criminals are using convincing fake wallet screens to steal recovery phrases and login data linked to the CastleLoader campaign.
Cybersecuritynews

More articles in this cluster (2)

Following this threat?

Track CastleLoader in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed