Malware, Critical Infrastructure Security

Novel CastleLoader variant facilitates extensive critical infrastructure compromise

Privacy concept: pixelated words Malware on digital background, 3d render

HackRead reports that U.S. government agencies and European critical infrastructure entities accounted for most of the 469 devices infected with a more clandestine version of the CastleLoader malware loader.

Intrusions involved the exploitation of the ClickFix social engineering technique in fraudulent update or verification pop-ups to lure targets into executing CastleLoader, which usually takes the guise of an Inno Setup-using package and runs an AutoIT script for subsequent compromise, according to ANY.RUN researchers. CastleLoader then proceeds to hijack the Windows tool "jsc.exe" with malicious code before communicating with its command-and-control server for the retrieval of information-stealing payloads and remote access trojans.

With the memory-based concealment of CastleLoader making the malware undetectable by traditional antivirus systems, organizations have been urged by security experts to not only bolster defenses against technical backdoors but also increase vigilance on spurious pop-up alerts that could facilitate malware injections.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Adware

You can skip this ad in 5 seconds