CastleBot is a fast-evolving malware framework sold as part of a Malware-as-a-Service operation, giving cybercriminals a powerful, flexible tool to launch large-scale attacks. First emerging in early 2025, it spreads mainly through fake software installers promoted via SEO poisoning, tricking victims into downloading it. Once on a system, CastleBot runs through multiple stages, starting with a lightweight stager, followed by a loader, and ending with a core backdoor capable of stealing information, deploying more malware, and laying the groundwork for ransomware. It communicates with its operators over encrypted channels, can adapt tasks mid-campaign, and uses advanced techniques to evade detection. Linked to campaigns delivering other dangerous threats like NetSupport RAT and WarmCookie, CastleBot’s modular design and rapid development make it a growing threat in today’s cybercrime ecosystem.
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox