Malware, Threat Intelligence

Nascent CastleLoader operations strengthened with new trojan

Cyber security concept. Toy horse on a digital screen, symbolizes the attack of the Trojan virus. 3D illustration.

Threat actor TAG-150 has advanced its CastleLoader malware operations with the development of a pair of CastleRAT trojan variants enabling system data exfiltration, command execution, and further payload deployment, The Hacker News reports.

More advanced of the CastleRAT variants is the C-based iteration, which could facilitate keystroke logging, screenshot capturing, file uploads and downloads, and cryptocurrency clipping, a report from Recorded Future's Insikt Group revealed.

CastleRAT's C variant also expands upon the data querying scope of the Python-based version, also known as PyNightshade and NightshadeC2, although the removal of certain data targets has been observed in newer forms of the C variant.

Such findings come as eSentire researchers detailed the use of .NET loader exploiting UAC Prompt Bombing and other techniques to deliver NightShadeC2, which could compromise Chromium- and Gecko-based browsers' credentials and cookies. Further investigation is still necessary to discover the distribution of CastleRAT trojans to other illicit actors.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds