CastleLoader Campaign Uses NeedleStealer to Target Crypto Users
Article Content
- •CastleLoader malware now deploys NeedleStealer to steal crypto wallet seeds.
- •Attackers use fake wallet screens and browser extensions to harvest sensitive data.
- •The campaign primarily targets Windows devices through deceptive software installers.
The CastleLoader malware campaign has evolved, deploying the NeedleStealer framework to steal cryptocurrency wallet seed phrases and hijack browser sessions. This operation targets Windows devices through fake software installers and deceptive prompts. Recent findings from Huntress and LevelBlue confirm that CastleLoader remains a primary delivery mechanism for multi-stage intrusions. Attackers use convincing fake wallet screens and browser extensions to harvest sensitive information. The scope of the attack is significant, affecting numerous users who interact with cryptocurrency applications. Current reports indicate that the campaign is ongoing, with new tools developed in Rust and Golang being utilized. Security professionals are advised to remain vigilant against these tactics.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CastleLoader in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
SloppyRAT: New Remote Access Trojan Fuels Ransomware Operations In June 2026, Zscaler ThreatLabz identified SloppyRAT, a new remote access trojan (RAT) used in ransomware attacks. Delivered through a multi-stage ClickFix infection chain, SloppyRAT employs advanced evasion techniques, including encrypted code and indirect Windows system calls. The malware allows attackers to…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…