Published on October 9, 2026

CastleStealer Malware Uses Browser Protection Bypass and Remote Shell to Expand Attacker Access


Severity

Medium

Detail

Flashpoint researchers have published an analysis detailing recent updates to CastleStealer, an emerging C#-based information stealer that has evolved to incorporate advanced browser protection bypasses and remote shell capabilities. First observed in April 2026 spreading via ClickFix social-engineering lures, the malware transitioned to malicious Google Ads targeting Node.js software searches, employing loaders like OXLOADER to execute in memory.

CastleStealer has evolved beyond passive credential harvesting, functioning as an interactive remote access tool that can execute system commands, download secondary payloads, and exfiltrate stolen data through small, AES-encrypted network transmissions.

How?

The infection chain begins when a victim executes a malicious batch file or loader delivered through drive-by downloads or malicious ads. Upon execution, CastleStealer performs an initial system check for the Russian (ru-RU) Multilingual User Interface language. If the environment passes inspection, the malware gathers basic host details and registers with its command-and-control (C2) server using a unique build UUID.

Once registered, CastleStealer targets a broad array of sensitive data stored across Chromium-based and Firefox browsers, including saved logins, session cookies, web forms, browsing history, and extension data. Notably, updated samples bypass Chromium’s App-Bound Encryption by abusing Chrome’s IElevator COM interface, allowing the stealer to decrypt app-bound cookies and protected data.

Beyond browsers, CastleStealer extracts configuration files from Steam (config.vdf, loginusers.vdf), data from local Telegram and Discord AppData directories, and scans local files for crypto wallet identifiers while skipping backup archives.

In addition to data collection, CastleStealer operates as a basic remote shell. Threat actors can push arbitrary shell commands, deliver local files for execution, or instruct the malware to download and launch secondary payloads from remote URLs.

To evade network-based detection, CastleStealer avoids creating large output archives; instead, it streams collected data in smaller, AES-encrypted chunks over raw TCP sockets. After completing its operational tasks, the stealer executes a ping-delay self-deletion routine to erase its binary from the host.

Conclusion

CastleStealer’s evolution from a standard info stealer into an interactive remote access threat demonstrates the growing complexity of commodity loader and stealer workflows. Security teams must monitor for unusual process execution, browser COM interface abuse, and stealthy outbound data transfers.

To defend against CastleStealer, organizations should monitor endpoint telemetry for unauthorized COM access to Chrome elevation components (IElevator) and track unexpected TCP connections originating from non-standard processes. Security teams should enforce ad-blocking and web filtering to prevent users from interacting with malicious installer ads or ClickFix prompt lures.

Additionally, incident response playbooks should require isolating impacted hosts, auditing command-line execution trees, resetting compromised web session cookies and corporate credentials, and inspecting endpoints for secondary payloads installed via the remote shell capability.

Source

https://cybersecuritynews.com/castlestealer-malware/