CastleLoader / NeedleStealer Crypto Wallet Malware Campaign
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·2KZBig…FVP2Summary
CastleLoader is an active multi-stage shellcode loader attributed to the threat actor cluster designated GrayBravo (also tracked as TAG-150) that has been operational since at least March 2025. In campaigns identified in July 2026, Arctic Wolf Labs documented the loader's expansion to deliver NeedleStealer, a modular framework comprising a Rust-based desktop wallet spoofer targeting Ledger, Trezor, and Exodus users and a Golang-based malicious browser extension installer that enables persistent session hijacking. The combined campaign uses ClickFix-style social engineering, digitally signed installers to strip Mark-of-the-Web protections, and in-memory payload injection to evade endpoint detection, with staged infrastructure bearing SSL certificates valid into August 2026 indicating ongoing operations.
Connected Entities
1 entities · 10 linked investigationsTimeline(9 events)
March 2025
TAG-150 (GrayBravo) earliest confirmed activity, deploying CastleLoader infrastructure
Recorded Future Insikt GroupMay 2025
CastleLoader campaigns actively targeting U.S. entities observed by PolySwarm; 469 of 1,634 attempted compromises succeed (28.7% infection rate)
PolySwarm BlogAugust 2025
CastleRAT Python variant first identified; TAG-150 expands from loader to full RAT capability
Recorded Future: From CastleLoader to CastleRATSeptember 2025
Recorded Future attributes campaign cluster to TAG-150, documenting four sub-clusters and four-tier C2 infrastructure
Recorded Future Insikt GroupDecember 2025
CastleLoader begins delivering LummaStealer; Bitdefender observes surge in infections peaking in India, the US, and Europe through January 2026
Bitdefender Labs30 April 2026
Huntress publishes BackgroundFix campaign analysis documenting ClickFix chain delivering CastleLoader, CastleStealer, and NetSupport RAT via fake background-removal websites
Huntress27 July 2026
Arctic Wolf Labs publishes expanded CastleLoader analysis identifying three new campaigns (Urutyka, Garrigin, Noidret) and the NeedleStealer framework with Rust wallet spoofer and Golang browser extension components
Arctic Wolf Labs28 July 2026
GBHackers and CyberPress report on the NeedleStealer connection and MOTW-stripping via signed installers, noting staged infrastructure with SSL certificates valid into August 2026
GBHackers / CyberPressAugust 2026
As of this investigation date, kaneta.cc and monblare.com infrastructure retains valid SSL certificates and is assessed to be staged for active or imminent deployment
Arctic Wolf Labs (via SOC Prime)Decision Log
- hash: 42uvZJVPgjzk41jRKuRT9QT5xroJ1Vkqm8J593BTzoqh
This investigation is cryptographically anchored to the Solana blockchain (1 event). 15 of 15 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/1/2026, 11:05:17 PM
last updated: 8/2/2026, 10:23:29 AM
3 viewsavoid.net — verified advice for a post-truth world