Skip to main content
AVOID.NET

CastleLoader / NeedleStealer Crypto Wallet Malware Campaign

avoid.net/castleloader-needlestealer-crypto-wallet-malware-campaign0/100·88% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·2KZBig…FVP2

Summary

CastleLoader is an active multi-stage shellcode loader attributed to the threat actor cluster designated GrayBravo (also tracked as TAG-150) that has been operational since at least March 2025. In campaigns identified in July 2026, Arctic Wolf Labs documented the loader's expansion to deliver NeedleStealer, a modular framework comprising a Rust-based desktop wallet spoofer targeting Ledger, Trezor, and Exodus users and a Golang-based malicious browser extension installer that enables persistent session hijacking. The combined campaign uses ClickFix-style social engineering, digitally signed installers to strip Mark-of-the-Web protections, and in-memory payload injection to evade endpoint detection, with staged infrastructure bearing SSL certificates valid into August 2026 indicating ongoing operations.

Have evidence about CastleLoader / NeedleStealer Crypto Wallet Malware Campaign?

Timeline(9 events)

March 2025

TAG-150 (GrayBravo) earliest confirmed activity, deploying CastleLoader infrastructure

Recorded Future Insikt Group

May 2025

CastleLoader campaigns actively targeting U.S. entities observed by PolySwarm; 469 of 1,634 attempted compromises succeed (28.7% infection rate)

PolySwarm Blog

August 2025

CastleRAT Python variant first identified; TAG-150 expands from loader to full RAT capability

Recorded Future: From CastleLoader to CastleRAT

September 2025

Recorded Future attributes campaign cluster to TAG-150, documenting four sub-clusters and four-tier C2 infrastructure

Recorded Future Insikt Group

December 2025

CastleLoader begins delivering LummaStealer; Bitdefender observes surge in infections peaking in India, the US, and Europe through January 2026

Bitdefender Labs

30 April 2026

Huntress publishes BackgroundFix campaign analysis documenting ClickFix chain delivering CastleLoader, CastleStealer, and NetSupport RAT via fake background-removal websites

Huntress

27 July 2026

Arctic Wolf Labs publishes expanded CastleLoader analysis identifying three new campaigns (Urutyka, Garrigin, Noidret) and the NeedleStealer framework with Rust wallet spoofer and Golang browser extension components

Arctic Wolf Labs

28 July 2026

GBHackers and CyberPress report on the NeedleStealer connection and MOTW-stripping via signed installers, noting staged infrastructure with SSL certificates valid into August 2026

GBHackers / CyberPress

August 2026

As of this investigation date, kaneta.cc and monblare.com infrastructure retains valid SSL certificates and is assessed to be staged for active or imminent deployment

Arctic Wolf Labs (via SOC Prime)
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 15 of 15 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/1/2026, 11:05:17 PM

last updated: 8/2/2026, 10:23:29 AM

3 views

avoid.net — verified advice for a post-truth world