CastleStealer Adds Chromium Encryption Bypass and Remote Shell
Flashpoint says CastleStealer, first seen in April 2026, now bypasses Chromium app-bound encryption and can run remote commands.
Flashpoint says CastleStealer, a C# information stealer first publicly identified in April 2026, now bypasses Chromium app-bound encryption and includes a basic remote shell. Initial delivery used a ClickFix campaign and CastleLoader; by June, malicious Google ads for Node.js directed users to fake installers that dropped a batch file and multi-stage OXLOADER, which loaded CastleStealer in memory. Newer samples abuse Chrome’s IElevator COM interface and collect Chromium and Firefox data along with Steam, Discord, and Telegram files; one report also lists wallet-related files. Operators can run shell commands, execute files, or download further payloads, while data leaves in small AES-encrypted raw TCP packets before the malware deletes itself. One source specifies AES-128-CBC and a check for the ru-RU language, details the other report does not state. Flashpoint has not observed widespread adoption.
- CastleStealer is a C# infostealer first publicly identified in April 2026.
- Newer builds bypass Chromium app-bound encryption through Chrome’s IElevator COM interface.
- A basic remote shell can run commands, execute files, or download and launch further payloads.
- Stolen data is sent in small AES-encrypted packets over raw TCP; one report specifies AES-128-CBC.
- Delivery moved from an April ClickFix campaign using CastleLoader to June malicious Google ads and fake Node.js installers that drop a batch file and multi-stage OXLOADER, which loads CastleStealer in memory.
- Collected data includes Chromium and Firefox material plus Steam, Discord, Telegram, and, in one report, wallet-related files.
- One report says the malware checks for the ru-RU language; both say it deletes itself after exfiltration.
- Flashpoint has not observed widespread adoption.
Coverage timelineoldest first · each row is one article
- · 1d agoCastleStealer Malware Bypasses Chromium ABE and Adds Remote Command Execution Capabilities
GBHackers· 56
CastleStealer now bypasses Chromium app-bound encryption, runs remote commands, and exfiltrates data over encrypted TCP.
- · 1d agoCastleStealer Malware Uses Browser Protection Bypass and Remote Shell to Expand Attacker Access
Cyber Security News· 62
CastleStealer now bypasses Chromium App-Bound Encryption and adds a remote shell on Windows.