⤷ Title: CastleLoader Unleashed: New Stealthy Malware Loader Leverages ClickFix & Fake GitHub for Widespread Infections
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 23:28:17 +0000
════════════════════════
⌗ Tags: #Malware #CastleLoader #ClickFix #cybersecurity #Github #Infostealer #Loader #malware #phishing #RAT #threat intelligence
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 27 Jul 2025 23:28:17 +0000
════════════════════════
⌗ Tags: #Malware #CastleLoader #ClickFix #cybersecurity #Github #Infostealer #Loader #malware #phishing #RAT #threat intelligence
Penetration Testing Tools
CastleLoader Unleashed: New Stealthy Malware Loader Leverages ClickFix & Fake GitHub for Widespread Infections
CastleLoader, a sophisticated malware loader, is actively exploiting ClickFix phishing and fake GitHub repos to distribute infostealers and RATs, with a 29% infection rate.
⤷ Title: New MaaS Operator TAG-150 Uses ClickFix Lure and Custom CastleLoader to Compromise 469 US Devices
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:19:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CastleLoader #CastleRAT #ClickFix #Darktrace #MaaS #Remote Access Trojan #social engineering #TAG_150
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:19:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CastleLoader #CastleRAT #ClickFix #Darktrace #MaaS #Remote Access Trojan #social engineering #TAG_150
Daily CyberSecurity
New MaaS Operator TAG-150 Uses ClickFix Lure and Custom CastleLoader to Compromise 469 US Devices
Darktrace exposed TAG-150, a new MaaS operator compromising 469+ US devices in months. The group uses ClickFix to trick victims into running malicious PowerShell that deploys the CastleLoader/CastleRAT backdoor.
⤷ Title: CastleLoader Malware Now Uses Python Loader to Bypass Security
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 09:28:08 +0000
════════════════════════
⌗ Tags: #Malware #Security #Blackpoint Cyber #CastleLoader #ClickFix #Cyber Attack #Cybersecurity #Python #Windows
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 09:28:08 +0000
════════════════════════
⌗ Tags: #Malware #Security #Blackpoint Cyber #CastleLoader #ClickFix #Cyber Attack #Cybersecurity #Python #Windows
Hackread
CastleLoader Malware Now Uses Python Loader to Bypass Security
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: CastleLoader PhaaS: GrayBravo Escalates Attacks on Logistics & Booking.com
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 10:28:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Booking.com #CastleLoader #cybercrime #GrayBravo #Logistics #Malware_as_a_Service #PhaaS #phishing #Recorded Future #TAG_160
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 10:28:44 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Booking.com #CastleLoader #cybercrime #GrayBravo #Logistics #Malware_as_a_Service #PhaaS #phishing #Recorded Future #TAG_160
Penetration Testing Tools
CastleLoader PhaaS: GrayBravo Escalates Attacks on Logistics & Booking.com
The cybercriminal group GrayBravo, formerly known as TAG-150, continues to evolve at a rapid pace, demonstrating a high
⤷ Title: New CastleLoader Variant Linked to 469 Infections Across Critical Sectors
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 15 Jan 2026 13:03:14 +0000
════════════════════════
⌗ Tags: #Malware #Security #ANY RUN #backdoor #CastleLoader #Cyber Attack #Cybersecurity
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 15 Jan 2026 13:03:14 +0000
════════════════════════
⌗ Tags: #Malware #Security #ANY RUN #backdoor #CastleLoader #Cyber Attack #Cybersecurity
Hackread
New CastleLoader Variant Linked to 469 Infections Across Critical Sectors
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: The Human Hack: LummaStealer Returns with Deceptive “ClickFix” Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 00:18:53 +0000
════════════════════════
⌗ Tags: #Malware #Bitdefender #CAPTCHA Fraud #CastleLoader #ClickFix #Cybercrime #Infostealer #LummaStealer #Malware_as_a_Service #phishing #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 13 Feb 2026 00:18:53 +0000
════════════════════════
⌗ Tags: #Malware #Bitdefender #CAPTCHA Fraud #CastleLoader #ClickFix #Cybercrime #Infostealer #LummaStealer #Malware_as_a_Service #phishing #social engineering
Daily CyberSecurity
The Human Hack: LummaStealer Returns with Deceptive "ClickFix" Attacks
LummaStealer is back, evading takedowns with "ClickFix" tactics. Bitdefender reveals how fake CAPTCHAs trick users into running malware. Stay alert.
⤷ Title: CastleLoader Malware Now Delivers NeedleStealer Wallet and Browser Spoofers
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 06:11:48 +0000
════════════════════════
⌗ Tags: #Malware #Arctic Wolf #CastleLoader #CASTLESTEALER #ClickFix #crypto wallet spoofer #Infostealer #malware loader #NeedleStealer #NetSupport RAT
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 06:11:48 +0000
════════════════════════
⌗ Tags: #Malware #Arctic Wolf #CastleLoader #CASTLESTEALER #ClickFix #crypto wallet spoofer #Infostealer #malware loader #NeedleStealer #NetSupport RAT
Daily CyberSecurity
CastleLoader Malware Now Delivers NeedleStealer Wallet and Browser Spoofers
At a glance Malware family CastleLoader (loader); payloads include CastleStealer, NetSupport RAT, Lobshot, and NeedleStealer Threat actor Not named in this report; the loader is publicly tied to a…