Arctic Wolf Labs has tracked a cluster of CastleLoader campaigns and identified significant updates to the infection chain. Three campaigns (Urutyka, Garrigin, Noidret) are documented, with the Noidret campaign being the most notable for introducing two new NeedleStealer payloads: a Rust-based desktop cryptocurrency wallet spoofer targeting Ledger, Trezor, and Exodus users via fake seed phrase prompts, and a Golang-based malicious browser extension installer enabling persistent session token and credential theft. These mark the first use of Rust and Golang tooling in this campaign cluster. The report also covers a new shellcode loader variant distributed via digitally signed installers using fraudulently obtained code-signing certificates, staged infrastructure domains, and detailed IOCs. Defensive recommendations include blocking known infrastructure, enforcing application allowlisting, monitoring PowerShell and IronPython activity, and restricting Node.js execution outside development environments.