CastleRAT Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
8
occurrences
First Seen
November 27, 2025
Last Seen
February 11, 2026

Related Threat Clusters

  • CastleRAT Malware Targets Windows Systems for Remote Access

    Hackers are deploying CastleRAT malware to compromise Windows systems, enabling remote access. This malware poses a significant risk to users, as it can facilitate unauthorized control over infected machines. The attack…

    2 articles · Updated December 5, 2025
  • UK Retail Cyber Attacks Show No Seasonal Spike Amid Holiday Concerns

    Analysis of cybersecurity incidents in the UK retail and manufacturing sectors reveals that 1,381 breaches occurred between Q3 2024 and Q2 2025, with no significant concentration around major shopping events. Security…

    61 articles · Updated November 28, 2025
  • LummaStealer Infections Rise Following CastleLoader Campaigns

    LummaStealer infections have surged due to social engineering campaigns utilizing the ClickFix technique to distribute CastleLoader malware. This infostealer, operating as a malware-as-a-service platform, had previously…

    7 articles · Updated February 11, 2026
  • Shanya Crypter Emerges as a New Ransomware Threat

    The Shanya crypter, also known as VX Crypt, has been identified as a new packer-as-a-service gaining popularity among ransomware groups. First observed in late 2024, it is designed to evade security detections and…

    3 articles · Updated December 8, 2025
  • CastleLoader Malware Expands Operations Targeting Logistics and Hospitality Sectors

    GrayBravo, previously known as TAG-150, has expanded its CastleLoader malware deployment across four distinct threat activity clusters since March 2025. The malware targets industries such as logistics and hospitality,…

    2 articles · Updated December 11, 2025
  • Phishing Campaign Exploits Microsoft Teams Notifications

    A coordinated phishing campaign is targeting Microsoft Teams users by exploiting the platform's notification system. This method allows attackers to bypass traditional security measures, increasing the risk for users…

    5 articles · Updated December 5, 2025
  • Cyber Monday 2025: Surge in Online Scams Targeting Shoppers

    As Cyber Monday approaches, online shoppers are facing increased risks from cybercriminals exploiting the surge in digital purchases. Security experts warn of fraudulent websites, phishing emails, and insecure payment…

    7 articles · Updated November 21, 2025

Recent Intelligence Reports

  • LummaStealer infections surge after CastleLoader malware campaigns — Bleepingcomputer · February 11, 2026
  • Activity of CastleLoader expands amid improvements — Scworld · December 11, 2025
  • Ransomware gangs turn to Shanya EXE packer to hide EDR killers — Bleepingcomputer · December 9, 2025
  • Shanya crypter emerges as new threat in ransomware toolkits — Scworld · December 8, 2025
  • Hackers Using CastleRAT Malware to Attack Windows Systems and Gain Remote Access — Cybersecuritynews · December 5, 2025
  • Hackers Exploiting Microsoft Teams Notifications to Deliver CallBack Phishing Attack — Cybersecuritynews · December 5, 2025
  • Hackers Using CastleRAT Malware to Attack Windows Systems and Gain Remote Access — Gbhackers · December 5, 2025
  • From Amazon to Louis Vuitton: How Darktrace Detects Black Friday Phishing Attacks — Darktrace · November 27, 2025

CVSS v3.1 Breakdown