Arctic Wolf Labs has discovered new CastleLoader campaigns employing digitally signed installers, Mark-of-the-Web (MotW) removal, and in-memory shellcode injection for delivering malware. This activity is part of an expanding CastleStealer, PythonRAT, NetSupport RAT, and newly observed NeedleStealer payload cluster linked to CastleLoader. The multi-stage loader often spreads through fake software installers, ClickFix lures, and obfuscated PowerShell scripts.
Multiple malicious installers linked to this infrastructure were found with valid digital signatures, including certificates from Mahu Agro and TECHNOLOGY APPRAISALS LIMITED. CastleLoader evades MotW by bypassing code signing checks. A PowerShell downloader creates a fake Microsoft Edge update folder at %ProgramData%\EdgeUpdate\, downloads traffic1.exe, strips the Zone.Identifier alternate data stream, and runs the hidden executable.
This initial PowerShell stager (click to enlarge) is part of an attack that aims to bypass security warnings and SmartScreen checks by leveraging Windows' Mark-of-the-Web mechanism. A second component, written in Golang, installs malicious browser extensions while adding benign-looking ones to avoid suspicion. These extensions can maintain access at the browser level, steal session tokens, and capture credentials even after users reset their passwords.
Utilizing ANY.RUN’s SOC investigation capabilities, this approach helps uncover blind spots in security measures and mitigate threats earlier to minimize response costs and business disruptions.












