From CastleLoader to CastleRAT: TAG-150 Advances Operations with MultiRecorded Future·Jun 22, 00:00 UTC · Jun 22, 2025Malware30
Node.js Malware Campaign Targets Crypto Users with Fake Binance and TradingView InstallersThe Hacker News·Apr 17, 08:57 UTC · Apr 17, 2025Malware30
GrayBravo’s CastleLoader Activity Clusters Target Multiple IndustriesRecorded Future·Oct 9, 00:00 UTC · Oct 9, 2025Malware30
TAG-150 Develops CastleRAT in Python and C, Expanding CastleLoader Malware OperationsThe Hacker News·Sep 6, 11:36 UTC · Sep 6, 2025Malware130
New Malware Campaign Uses Cloudflare Tunnels to Deliver RATs via Phishing ChainsThe Hacker News·Jun 19, 16:44 UTC · Jun 19, 2025Malware30
PEAKLIGHT Downloader Deployed in Attacks Targeting Windows with Malicious Movie DownloadsThe Hacker News·Sep 26, 03:54 UTC · Sep 26, 2024Malware30
Cybercriminals Exploit Popular Software Searches to Spread FakeBat MalwareThe Hacker News·Aug 20, 03:55 UTC · Aug 20, 2024Malware30
FakeBat Loader Malware Spreads Widely Through DriveThe Hacker News·Jul 8, 14:56 UTC · Jul 8, 2024Malware30
Hackers Using MSIX App Packages to Infect Windows PCs with GHOSTPULSE MalwareThe Hacker News·Oct 30, 06:58 UTC · Oct 30, 2023Malware30
Google shuts down malicious ad posing as Brave browser but delivering malwareThe Record·Dec 14, 00:00 UTC · Dec 14, 2022Malware30