Data Security, Malware

LummaStealer surges with CastleLoader and ClickFix techniques

LummaStealer infections have seen a significant increase, primarily utilizing the ClickFix social engineering technique to deploy the CastleLoader malware. This resurgence follows a major disruption of the LummaStealer malware-as-a-service platform in May 2025, which saw over 2,300 domains seized. Despite law enforcement efforts, the operation resumed in July 2025 and has since scaled considerably, as covered by Bleeping Computer.

The current LummaStealer campaigns are heavily reliant on CastleLoader, a modular malware loader that executes payloads in memory with extensive obfuscation. CastleLoader, which emerged in early 2025, has been used to distribute various infostealers and remote access trojans. It employs sophisticated techniques to evade detection, including environment checks and adaptive persistence mechanisms. The ClickFix method, a key infection vector, tricks users into executing malicious PowerShell commands by presenting fake CAPTCHA or verification pages. These commands download and run CastleLoader, which then delivers LummaStealer. The malware targets sensitive data such as credentials, cryptocurrency wallet details, and session cookies.

The renewed activity of LummaStealer, amplified by CastleLoader and ClickFix, highlights the persistent threat of infostealer operations and the adaptability of cybercriminals. Organizations should prioritize educating employees about phishing and social engineering tactics and implement strong security protocols to mitigate the risk of credential theft and data breaches.

Source: Bleeping Computer

You can skip this ad in 5 seconds