CastleStealer Malware Uses Browser Protection Bypass and Remote Shell to Expand Attacker Access
CastleStealer now bypasses Chromium App-Bound Encryption and adds a remote shell on Windows.
Flashpoint analyzed newer CastleStealer samples, a C# information stealer first identified in April 2026 in a ClickFix campaign that used CastleLoader. By June, malicious Google ads for Node.js sent users to fake installers that delivered a batch file and OXLOADER, which loaded CastleStealer in memory. New samples abuse Chrome’s IElevator COM interface to bypass Chromium App-Bound Encryption and collect Chromium and Firefox data, plus Steam, Discord, Telegram, and wallet-related files. Operators can run shell commands, execute files, or download further payloads, while data leaves in small AES-encrypted raw TCP chunks before self-deletion.