CastleLoader / NeedleStealer Crypto Wallet Malware Campaign
Summary
CastleLoader is an active multi-stage shellcode loader attributed to the threat actor cluster designated GrayBravo (also tracked as TAG-150) that has been operational since at least March 2025. In campaigns identified in July 2026, Arctic Wolf Labs documented the loader's expansion to deliver NeedleStealer, a modular framework comprising a Rust-based desktop wallet spoofer targeting Ledger, Trezor, and Exodus users and a Golang-based malicious browser extension installer that enables persistent session hijacking. The combined campaign uses ClickFix-style social engineering, digitally signed installers to strip Mark-of-the-Web protections, and in-memory payload injection to evade endpoint detection, with staged infrastructure bearing SSL certificates valid into August 2026 indicating ongoing operations.
Connected Entities
1 entities · 10 linked investigationsTimeline(9 events)
2025-03-01
TAG-150 (GrayBravo) earliest confirmed activity, deploying CastleLoader infrastructure
Recorded Future Insikt Group2025-05-01
CastleLoader campaigns actively targeting U.S. entities observed by PolySwarm; 469 of 1,634 attempted compromises succeed (28.7% infection rate)
PolySwarm Blog2025-08-01
CastleRAT Python variant first identified; TAG-150 expands from loader to full RAT capability
Recorded Future: From CastleLoader to CastleRAT2025-09-01
Recorded Future attributes campaign cluster to TAG-150, documenting four sub-clusters and four-tier C2 infrastructure
Recorded Future Insikt Group2025-12-01
CastleLoader begins delivering LummaStealer; Bitdefender observes surge in infections peaking in India, the US, and Europe through January 2026
Bitdefender Labs2026-04-30
Huntress publishes BackgroundFix campaign analysis documenting ClickFix chain delivering CastleLoader, CastleStealer, and NetSupport RAT via fake background-removal websites
Huntress2026-07-27
Arctic Wolf Labs publishes expanded CastleLoader analysis identifying three new campaigns (Urutyka, Garrigin, Noidret) and the NeedleStealer framework with Rust wallet spoofer and Golang browser extension components
Arctic Wolf Labs2026-07-28
GBHackers and CyberPress report on the NeedleStealer connection and MOTW-stripping via signed installers, noting staged infrastructure with SSL certificates valid into August 2026
GBHackers / CyberPress2026-08-01
As of this investigation date, kaneta.cc and monblare.com infrastructure retains valid SSL certificates and is assessed to be staged for active or imminent deployment
Arctic Wolf Labs (via SOC Prime)Decision Log
- #1publish⛓ pending8/1/2026, 11:05:28 PMhash: 42uvZJVPgjzk41jRKuRT9QT5xroJ1Vkqm8J593BTzoqh
15 of 15 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/1/2026, 11:05:17 PM
last updated: 8/2/2026, 10:23:29 AM
avoid.net — verified advice for a post-truth world