CASTLELOADER is a malware family that delivers various payloads such as NeedleStealer and NetSupport RAT, targeting Windows users and cryptocurrency wallets through fake software installers and ClickFix-style lures. The malware uses advanced techniques including in-memory staging, encrypted command-and-control (C2) communication, and can steal wallet seeds and hijack browser sessions.
New campaigns have introduced NeedleStealer, which utilizes Rust and Golang code to spoof cryptocurrency wallet interfaces and hijack browser data. The importance of defending against these threats includes blocking suspicious executables, monitoring scripting activities, and training users to recognize fraudulent prompts.