Threat Advisories:
🎧 Podcast: This Month's Threats in 10 Min! Emerging Threat Intel Audio Briefing - Listen & Defend Now →
👥 Play Count: Loading...

CastleBot Rising: The Evolving Malware-as-a-Service Threat

Amber | Attack Report
Download PDF

CastleBot is a fast-evolving malware framework sold as part of a Malware-as-a-Service operation, giving cybercriminals a powerful, flexible tool to launch large-scale attacks. First emerging in early 2025, it spreads mainly through fake software installers promoted via SEO poisoning, tricking victims into downloading it. Once on a system, CastleBot runs through multiple stages, starting with a lightweight stager, followed by a loader, and ending with a core backdoor capable of stealing information, deploying more malware, and laying the groundwork for ransomware. It communicates with its operators over encrypted channels, can adapt tasks mid-campaign, and uses advanced techniques to evade detection. Linked to campaigns delivering other dangerous threats like NetSupport RAT and WarmCookie, CastleBot’s modular design and rapid development make it a growing threat in today’s cybercrime ecosystem.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox