Arctic Wolf
Read post

Expanding the Castle: New Campaigns, New Tooling, and the NeedleStealer Connection

Arctic Wolf Labs has tracked a cluster of CastleLoader campaigns and identified significant updates to the infection chain. Three campaigns (Urutyka, Garrigin, Noidret) are documented, with the Noidret campaign being the most notable for introducing two new NeedleStealer payloads: a Rust-based desktop cryptocurrency wallet spoofer targeting Ledger, Trezor, and Exodus users via fake seed phrase prompts, and a Golang-based malicious browser extension installer enabling persistent session token and credential theft. These mark the first use of Rust and Golang tooling in this campaign cluster. The report also covers a new shellcode loader variant distributed via digitally signed installers using fraudulently obtained code-signing certificates, staged infrastructure domains, and detailed IOCs. Defensive recommendations include blocking known infrastructure, enforcing application allowlisting, monitoring PowerShell and IronPython activity, and restricting Node.js execution outside development environments.

    #golang#rust#malware
Jul 27•12m read time•From arcticwolf.com
Post cover image
Table of contents
SummaryRecommendationsAppendix
307 Impressions
Arctic Wolf's image
Arctic Wolf

ArcticWolf's platform is a central hub for cybersecurity professionals, offering insights into manag...

77 Followers

•

107 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard