Skip to main content
Sign in

CastleLoader / NeedleStealer Crypto Wallet Malware Campaign

avoid.net/castleloader-needlestealer-crypto-wallet-malware-campaign0/100·88% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Summary

CastleLoader is an active multi-stage shellcode loader attributed to the threat actor cluster designated GrayBravo (also tracked as TAG-150) that has been operational since at least March 2025. In campaigns identified in July 2026, Arctic Wolf Labs documented the loader's expansion to deliver NeedleStealer, a modular framework comprising a Rust-based desktop wallet spoofer targeting Ledger, Trezor, and Exodus users and a Golang-based malicious browser extension installer that enables persistent session hijacking. The combined campaign uses ClickFix-style social engineering, digitally signed installers to strip Mark-of-the-Web protections, and in-memory payload injection to evade endpoint detection, with staged infrastructure bearing SSL certificates valid into August 2026 indicating ongoing operations.

Have evidence about CastleLoader / NeedleStealer Crypto Wallet Malware Campaign?

Timeline(9 events)

2025-03-01

TAG-150 (GrayBravo) earliest confirmed activity, deploying CastleLoader infrastructure

Recorded Future Insikt Group

2025-05-01

CastleLoader campaigns actively targeting U.S. entities observed by PolySwarm; 469 of 1,634 attempted compromises succeed (28.7% infection rate)

PolySwarm Blog

2025-08-01

CastleRAT Python variant first identified; TAG-150 expands from loader to full RAT capability

Recorded Future: From CastleLoader to CastleRAT

2025-09-01

Recorded Future attributes campaign cluster to TAG-150, documenting four sub-clusters and four-tier C2 infrastructure

Recorded Future Insikt Group

2025-12-01

CastleLoader begins delivering LummaStealer; Bitdefender observes surge in infections peaking in India, the US, and Europe through January 2026

Bitdefender Labs

2026-04-30

Huntress publishes BackgroundFix campaign analysis documenting ClickFix chain delivering CastleLoader, CastleStealer, and NetSupport RAT via fake background-removal websites

Huntress

2026-07-27

Arctic Wolf Labs publishes expanded CastleLoader analysis identifying three new campaigns (Urutyka, Garrigin, Noidret) and the NeedleStealer framework with Rust wallet spoofer and Golang browser extension components

Arctic Wolf Labs

2026-07-28

GBHackers and CyberPress report on the NeedleStealer connection and MOTW-stripping via signed installers, noting staged infrastructure with SSL certificates valid into August 2026

GBHackers / CyberPress

2026-08-01

As of this investigation date, kaneta.cc and monblare.com infrastructure retains valid SSL certificates and is assessed to be staged for active or imminent deployment

Arctic Wolf Labs (via SOC Prime)
Provenance & Audit Trail
15 Wayback Archives

Decision Log

  • #1publish⛓ pending8/1/2026, 11:05:28 PM
    hash: 42uvZJVPgjzk41jRKuRT9QT5xroJ1Vkqm8J593BTzoqh

15 of 15 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/1/2026, 11:05:17 PM

last updated: 8/2/2026, 10:23:29 AM

avoid.net — verified advice for a post-truth world