CastleStealer: An Emerging Infostealer Growing More Sophisticated

In this post, we analyze the evolution of CastleStealer, including the sensitive data it targets, new techniques for bypassing browser protections, remote command capabilities, and an approach to exfiltration designed to help stolen data blend into network traffic.

First discovered in April 2026, CastleStealer is a C#-based information-stealing malware that has continued to add new capabilities since its emergence. Newer samples analyzed by Flashpoint can bypass app-bound encryption in Chromium-based browsers, execute commands remotely, and exfiltrate stolen information in small encrypted transmissions rather than a single large archive.

While Flashpoint has not yet identified a large influx of threat actors using CastleStealer, its continued development makes it an emerging threat worth watching. 

What We Know About CastleStealer

CastleStealer was first publicly identified in April 2026, when it was observed using ClickFix social engineering to deliver a Python script that executed a loader referred to as “CastleLoader.”

By June, the malware had appeared in a different distribution campaign. Threat actors used malicious advertisements to direct victims to fake Node.js installation websites, where a batch script masquerading as an installer ultimately downloaded and executed a newer loader known as OXLOADER.

Contents of downloaded batch script masquerading as a Node.js installer. (Source: Flashpoint)

OXLOADER employs several techniques designed to make analysis and detection more difficult, including multiple rounds of self-decryption, obfuscated API resolution, sandbox checks, and in-memory execution. Flashpoint analysts assess that the loaders used to deliver CastleStealer appear to be developed in-house and demonstrate significant technical ability around anti-analysis and stealth. 

But the delivery chain is only one part of CastleStealer’s evolution. Newer samples show that the infostealer itself has continued to expand what it can collect and what threat actors can do after a system is compromised.

What Data Does CastleStealer Target?

Once executed, CastleStealer first checks the system’s Multilingual User Interface (MUI) languages for Russian (ru-RU). It then connects to its command-and-control (C2) infrastructure and sends a handshake packet containing its build UUID and basic information about the infected host. After establishing the connection, it gathers additional information about the victim machine and sends it to the C2. 

From there, CastleStealer begins searching for sensitive information across browsers, applications, and files on the victim’s system.

For Chromium-based browsers, CastleStealer collects login data, cookies, browsing history, web data, and information stored by browser extensions. That includes extension IDs, IndexedDB data, and extension storage. 

The malware also targets:

  • Firefox: Login data, cookies, browsing history, and form history.
  • Steam: Files including config.vdf, loginusers.vdf, and local.vdf, which can contain sensitive account information and settings.
  • Discord and Telegram: CastleStealer searches APPDATA for directories associated with both applications.
  • Files on the victim system: The malware broadly collects files while excluding several file types and files containing “backup.” It places particular emphasis on files containing “wallet” in their names. Flashpoint – _Castlestealer_ In…

That browser targeting has also become more capable since CastleStealer was first discovered.

Bypassing App-Bound Encryption

One of the clearest examples of CastleStealer’s evolution is its ability to target data protected by newer browser security controls.

Earlier analysis found that CastleStealer could not steal data from updated browsers using app-bound encryption. Newer samples analyzed by Flashpoint now use Chrome’s IElevator COM interface to bypass that protection, a technique also used by other modern infostealers.

IElevator COM CLSIDs present for various Chromium-based browsers in newer CastleStealer samples. (Source: Flashpoint)

The change closes a meaningful limitation present in earlier CastleStealer samples and expands the browser data available to the malware.

From Infostealer to Remote Access

Newer CastleStealer samples also give threat actors capabilities beyond stealing information from an infected machine.

CastleStealer contains basic remote shell functionality that allows an operator to send a shell command to the victim system, provide a file for execution, or send the URL of another payload that CastleStealer will download and execute. 

CastleStealer remote command capabilities. (Source: Flashpoint)

That capability gives an attacker additional options after the initial compromise. Instead of ending the operation once targeted information has been collected, an operator can interact with the infected system and introduce additional payloads.

How CastleStealer Exfiltrates Stolen Data

CastleStealer also differs from many other infostealers in how it sends stolen information back to its operators.

Rather than collecting stolen data into an archive and transmitting it to a C2 server or Telegram channel, CastleStealer sends smaller amounts of collected data over raw TCP. The transmissions are encrypted using AES.

Flashpoint analysts assess that transmitting data this way may help CastleStealer avoid network detections associated with a single spike caused by a large data transfer. 

The network packets follow a straightforward structure:

{4-byte size} → {AES IV} → {Encrypted Data}

AES-128 CBC decryption of a CastleStealer network packet. (Source: Flashpoint)

Once CastleStealer completes its activity, it deletes itself using a common ping-delay self-deletion technique.

Protect Against Emerging Infostealers Using Flashpoint

CastleStealer’s development since its discovery illustrates how quickly an emerging infostealer can mature. Its operators have changed how the malware reaches victims, while the stealer itself has gained the ability to bypass browser protections, remotely execute commands and additional payloads, and exfiltrate stolen data in smaller encrypted transmissions.

CastleStealer has not yet seen the widespread adoption associated with more established infostealer families. But its trajectory makes it one to watch as its developers continue to improve both its collection capabilities and what operators can do after compromising a victim.

Flashpoint continuously monitors emerging malware, illicit communities, and threat actor infrastructure to identify these shifts as they happen. Request a demo to learn how Flashpoint’s primary source intelligence and analyst research help security teams identify emerging threats and respond before they become widespread.

See Flashpoint in Action

Get real-time curated data, expert analysis, and AI-driven insights to monitor threats across the surface, deep, and dark web—including closed sources.