Expanding the Castle: New Campaigns, New Tooling, and the NeedleStealer Connection
Arctic Wolf Labs tracked an expanding CastleLoader delivery cluster (Urutyka, Garrigin, Noidret campaigns) that uses obfuscated PowerShell stagers, embedded IronPython runtimes, and NSIS/NodeJS-based shellcode injectors to deploy CastleStealer, NetSupport RAT, Lobshot, and now NeedleStealer. NeedleStealer's newly observed Rust-based cryptocurrency wallet spoofer and Golang-based malicious browser extension installer represent a tactical shift toward high-value crypto targeting and persistent browser-layer access, delivered via digitally signed installers using fraudulently obtained code-signing certificates.
- domainavivtech[.]orgDomain observed pulling py-Castle payloads June 23-24, 2026
- domainclaudenell[.]netFinger domain identified June 24, 2026, likely staged infrastructure
- domainclaudettes[.]netFinger domain pointing to avivtech default3, likely staged infrastructure
- domaindrrajivparti[.]comNetSupport RAT C2 in Urutyka campaign
- domaineazysitebuilder[.]comNetSupport RAT C2 in Urutyka campaign
- domainebedidance[.]comNetSupport RAT C2 in Garrigin campaign
- domainfangorinaf[.]comDownload/C2 domain delivering NetSupport RAT in Noidret campaign
- domaingarrigin[.]comDownload server used in the Garrigin CastleLoader campaign
- domaingoodbytetelegramm[.]comDownload server used in Urutyka campaign
- domaingrenagana[.]comDownload server delivering CastleLoader Stage 2 shellcode (document1 payload) in Garrigin campaign
- domaingrorriner[.]comDownload server used in Garrigin campaign infrastructure
- domainhobtech[.]netStaged domain that was not delivering payloads when queried
- domainitalianhitech[.]comNetSupport RAT C2 in Noidret campaign
- domainkaneta[.]ccDomain with minimal traffic possibly staged for future campaign, related to signed installer infrastructure
- domainkileant[.]comShared C2 domain for both Rust and Golang NeedleStealer payloads in Noidret campaign; undetected on VirusTotal at time of analysis
- domainmonblare[.]comDormant domain hosted alongside kaneta[.]cc with no VT detections, possibly staged for future use
- domainnoidoret[.]comC2 domain decrypted from ChaCha20-encrypted configuration, used for bw-base payload delivery
- domainnoidret[.]comDownload server delivering NeedleStealer (Golang) 32-bit payload
- domainp-rala[.]comNetSupport RAT C2 in Noidret campaign
- domainpub-4d5f81bf79554aa7a2187e6ffbc9702a[.]r2[.]devCloudflare R2 CDN hosting traffic1.exe in Garrigin campaign
- domainpub-6728b11f74fd435f926ed25c5f2952bb[.]r2[.]devCloudflare R2 CDN used to host traffic1.msi download in Urutyka campaign
- domainquiantar[.]comDownload server delivering combined NeedleStealer Rust + Golang payloads
- domainqxvnrta[.]comC2 for new shellcode loader variant spread via digitally signed installers
- domainskipraid[.]comStaged domain found June 24, 2026, hosted on Cloudflare
- domainsocom-game[.]comNetSupport RAT C2 in Garrigin campaign
- domainstrainted[.]comDownload server delivering CastleStealer (net40) in Noidret campaign
- domainteamsvoicepremium[.]comFinger domain identified June 24, 2026, likely staged infrastructure
- domainthenugcompany[.]orgStaged domain observed pulling new CastleLoader stager
- domainurutyka[.]comDownload server hosting CastleLoader stage payloads for Urutyka campaign
- ip151[.]240[.]151[.]126Callback server for traffic1.msi delivery
- ip179[.]132[.]128[.]189CastleStealer (net40) C2 server in the Garrigin campaign
- ip216[.]107[.]139[.]188CastleStealer C2 for strainted[.]com in Noidret campaign
- ip84[.]201[.]6[.]21C2 IP associated with noidret.com NeedleStealer (Golang) delivery
- ip91[.]92[.]33[.]167Lobshot C2 server in the Urutyka campaign
- ip94[.]26[.]90[.]112Callback server for traffic1.exe delivery in Garrigin campaign
- sha2560c48fd6a18ad9c701b254bbdd412efbf7dfdd2be6534a61c14bce719d259df9fCastleLoader-related sample identified via YARA retrohunt, June 2026, 0 detections
- sha2562fcf553b9656523b3207c08cdf16f7be9a25e55cf8c29f5caf933151c9214367CastleLoader-related sample identified via YARA retrohunt, March 2026
- sha256d26ea6828cc01ae151d99bbee78c4e6d132e9077842a558bce3901fa0970d9beSigned malicious installer sample linked to kaneta.cc/monblare.com infrastructure
- sha256edff43ecdf7aa476331d925db04e68a2251920165a2109be9df91a56d86b87c7Reference sample for new shellcode loader variant contacting qxvnrta.com
- sha256fa67487da701ce1d61ee3abb84869f669a6c2aa50ca0148a3c4a87e667716638CastleLoader-related sample identified via YARA retrohunt, May 2026
- urlhxxp://151[.]240[.]151[.]126/dl-callback/wg868z9e/traffic1[.]msi/Callback URL used by PowerShell stager after MSI download
- urlhxxp://94[.]26[.]90[.]112/dl-callback/6dkcdpd7-4jacbuf9-prutgux4-2ybssc8v/traffic1[.]exe/1390903f57b21f346193aefbbfd36759Callback URL confirming successful traffic1.exe delivery
- urlhxxps://fangorinaf[.]com/XSeKAKD322445k2i/defaultDecrypted C2 URL for NetSupport RAT tasking in Noidret campaign
- urlhxxps://noidoret[.]com/6d6d2d17-d270-59c6-8b75-df011af08e58/bw-baseDecrypted C2 URL delivering NeedleStealer Golang browser payload
- urlhxxps://pub-4d5f81bf79554aa7a2187e6ffbc9702a[.]r2[.]dev/traffic1[.]exeCloudflare R2 download URL for fake Edge update installer in Garrigin campaign
- urlhxxps://pub-6728b11f74fd435f926ed25c5f2952bb[.]r2[.]dev/traffic1[.]msiMSI download URL for stage 2 payload in Urutyka campaign
- urlhxxps://quiantar[.]com/KsXmmKiN5N0j/desktop-wallet[.]binDecrypted C2 URL delivering NeedleStealer Rust desktop wallet spoofer binary
- urlhxxps://strainted[.]com/6d6d2d17-d270-59c6-8b75-df011af08e58/net40Decrypted C2 URL delivering CastleStealer net40 payload
- urlhxxps://urutyka[.]com/473070fa-6f82-5c2a-9dee-3db4be57110f/doc1Download URL for CastleLoader payload in Urutyka campaign
Detection / HunterAnthropic
What Happened
Security researchers at Arctic Wolf found that a known malware delivery tool called CastleLoader is now being used to spread a new set of malicious programs called NeedleStealer, which specifically targets cryptocurrency wallet users and web browsers. This affects anyone who might be tricked into downloading a fake software installer or running a suspicious command, and the attackers are using stolen or fraudulently obtained digital certificates to make their fake programs look trustworthy. This matters because the new tools can steal cryptocurrency wallet recovery phrases (which can lead to irreversible financial loss) and can maintain long-term access to victims' browsers even after passwords are changed. Organizations and individuals should be cautious about downloading software from unofficial sources, avoid running copy-pasted commands from websites (a technique called 'ClickFix'), and ensure security tools are configured to flag unusual installer behavior and unexpected script execution.
Key Takeaways
- CastleLoader campaigns (Urutyka, Garrigin, Noidret) now deliver NeedleStealer, a Rust/Golang framework, marking the first observed use of non-.NET tooling in this campaign cluster.
- The Noidret campaign introduces a Rust-based cryptocurrency hardware wallet spoofer (Ledger, Trezor, Exodus) and a Golang-based malicious browser extension installer, both delivered via a NodeJS-based shellcode injector.
- Campaigns use digitally signed installers with fraudulently obtained code-signing certificates (Mahu Agro, TECHNOLOGY APPRAISALS LIMITED) to bypass endpoint controls.
- Multiple staged/dormant domains (thenugcompany.org, skipraid.com, claudenell.net, claudettes.net, teamsvoicepremium.com, avivtech.org, hobtech.net, monblare.com, kaneta.cc) appear positioned for future operations.
- Infection chains rely on obfuscated PowerShell stagers, embedded IronPython runtimes, and Mark-of-the-Web (Zone.Identifier ADS) stripping combined with RunMRU registry key deletion to evade detection and cover tracks.
Affected Systems
- Windows desktop endpoints
- Users of hardware cryptocurrency wallets (Ledger, Trezor, Exodus, Atomic, Guarda, BitBox, Coinomi)
- Chromium-based browsers (extension installation)
- Organizations with unrestricted PowerShell/IronPython/NodeJS execution
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: Obfuscated PowerShell stager delivered (via ClickFix-style lure or fake installer) executes and unpacks a second-stage PS1 script
- Download/Staging: Script contacts a Cloudflare R2 or attacker-controlled download server to retrieve an MSI/EXE dropper (e.g., traffic1.msi/traffic1.exe) disguised as a legitimate update
- Execution: Dropper launches an embedded IronPython runtime or NSIS installer that decodes and executes a base64/XOR-obfuscated Python downloader script
- Injection: Python script downloads and reflectively injects CastleLoader stage 2 shellcode entirely in memory using ctypes-based heap allocation
- C2 Tasking: CastleLoader issues get_tasks requests to C2, retrieving RC4-encrypted payload manifests pointing to multiple download servers
- Payload Delivery: Final payloads (NetSupport RAT, Lobshot, CastleStealer, NeedleStealer Rust wallet spoofer, NeedleStealer Golang browser extension installer) are decrypted and deployed via NodeJS-based shellcode injectors or CLR injectors
- Persistence/Impact: NeedleStealer harvests cryptocurrency wallet recovery phrases via fake GUI prompts or installs malicious browser extensions for persistent session/credential theft, while RunMRU registry keys and Zone.Identifier ADS are deleted/stripped to evade detection
Detection Availability
- YARA Rules: Yes
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
- Platforms: Arctic Wolf Labs public GitHub repository
Arctic Wolf Labs developed YARA rules for shellcode loaders (used for retrohunting on VirusTotal) and references a public GitHub repository containing full IOC lists and MITRE ATT&CK mapping appendices; rule bodies are not reproduced in this report.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | Behaviors such as PowerShell spawning child processes, IronPython/NodeJS execution from ProgramData, in-memory shellcode injection via ctypes heap APIs, and registry key deletion should be visible to EDR with script-block logging and process ancestry telemetry, but in-memory-only stages and reflective injection reduce file-based detection. |
| Network Visibility | Medium | C2 traffic uses HTTP/HTTPS to attacker domains and Cloudflare R2 CDN, which may blend with legitimate cloud storage traffic; TLS 1.2 enforcement and RC4/AES/ChaCha20 encrypted payloads limit content inspection, but domain/IP-based network detection is feasible with threat intel feeds. |
| Detection Difficulty | Hard | The multi-stage, in-memory shellcode injection, use of legitimate-looking directories (%ProgramData%\EdgeUpdate), digitally signed installers, and non-.NET (Rust/Golang) payloads with low static detection rates make this cluster difficult to detect using signature-based tools alone; behavioral and telemetry-based detection is required. |
Required Log Sources
- PowerShell Script Block Logging (Event ID 4104)
- PowerShell Module Logging (Event ID 4103)
- Process creation logs (Sysmon Event ID 1 / Windows Event ID 4688)
- Network connection logs / DNS query logs
- File creation/modification logs (Sysmon Event ID 11)
- Registry modification logs (Sysmon Event ID 13)
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Look for PowerShell processes spawning from non-standard parent processes (e.g., Explorer, browsers) followed by heavily obfuscated Base64-encoded script blocks, consistent with initial stager execution. | PowerShell Script Block Logging, process creation with parent-child relationships | Initial Access / Execution (T1059.001) | Medium - legitimate admin scripts may also be obfuscated or use encoded arguments |
| Hunt for python.exe or ipyw32.exe (or similarly named embedded Python runtimes) executing from %ProgramData% or %APPDATA% directories, which is unusual for typical IronPython deployments. | Process creation logs, file path analysis | Execution (T1059.006) | Low - IronPython execution from user-writable temp/programdata directories is rare in legitimate environments |
| Monitor for node.exe execution from ProgramData or paths outside standard development directories, which may indicate NeedleStealer's NodeJS-based shellcode injector. | Process creation logs, file path/command-line analysis | Execution / Defense Evasion (T1105, T1055) | Low to Medium - depends on whether Node.js is a sanctioned runtime in the environment |
| Search for deletion of the RunMRU registry key or Zone.Identifier alternate data stream removal shortly after a file download, indicating anti-forensic and Mark-of-the-Web evasion behavior. | Registry modification logs (Sysmon Event ID 13), NTFS ADS monitoring | Defense Evasion (T1070.009, T1553.005) | Low - this specific registry deletion pattern is uncommon in benign software |
| Identify outbound HTTP/HTTPS requests to newly registered or low-reputation domains with invented, phonetically unusual names, or URI paths matching a GUID-plus-version pattern used for stager delivery. | DNS logs, proxy/firewall logs, URL pattern matching | Command and Control (T1071.001) | Medium - requires baseline of normal domain traffic to reduce false positives from legitimate new domains |
Control Gaps
- Code-signing validation alone will not block installers signed with fraudulently obtained certificates
- Static signature-based antivirus may have low detection rates against Rust/Golang binaries and AI-obfuscated code
- SmartScreen and Mark-of-the-Web protections can be bypassed via Zone.Identifier ADS stripping
- Standard application allowlisting that trusts %ProgramData% paths will not catch installers masquerading as legitimate update directories
Key Behavioral Indicators
- PowerShell or Python processes spawning from unexpected parent processes with large Base64-encoded variable assignments
- Presence of directories mimicking legitimate software update paths (e.g., EdgeUpdate) that were created recently and contain unsigned or unexpectedly signed executables
- Node.js runtime execution paired with ffi-rs or native crypto module usage outside development contexts
- Deletion of RunMRU registry values immediately following file execution
- In-memory heap allocation API calls (HeapCreate, HeapAlloc, RtlMoveMemory) invoked from scripting engines
False Positive Assessment
Medium - while specific indicators (domains, hashes, registry key deletion, unusual Node.js/IronPython execution paths) are highly distinctive, some behavioral signals such as PowerShell obfuscation or new domain traffic could overlap with legitimate administrative scripting or benign new software, requiring correlation with multiple indicators before high-confidence alerting.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting: consider blocking the listed domains and IPs at DNS/firewall/proxy layers and hunting for historical connections to this infrastructure.
- Consider isolating any hosts observed executing ipyw32.exe, node.exe from ProgramData/AppData, or unexpected PowerShell child processes, if your EDR supports host isolation.
- Evaluate whether recently downloaded installers claiming to be Microsoft Edge updates or similar legitimate software match verified vendor sources before allowing execution.
- Consider auditing endpoints for the presence of the identified file paths, registry key deletions, and browser extension IDs described in this report.
Infrastructure Hardening
- Evaluate enforcing application allowlisting to prevent execution of unsigned or unexpectedly signed binaries from %ProgramData% and other user-writable directories.
- Consider reviewing endpoint policy so that code-signing validity alone is not sufficient to bypass execution controls; pair certificate checks with reputation and behavioral analysis.
- If Node.js is not an expected runtime in your environment, consider blocking its execution via application control policy.
- Consider hunting for URL path patterns matching GUID-plus-version schemas historically used for stager delivery, as noted in the report.
User Protection
- Enable PowerShell Script Block Logging and Module Logging (Event IDs 4103/4104) where not already enabled, to improve visibility into obfuscated stager activity.
- Consider alerting on PowerShell or Python interpreters spawning from unusual parent processes or user-writable directories.
- Consider monitoring for Zone.Identifier ADS deletion events as a pre-execution evasion indicator.
- Evaluate deploying browser extension allowlisting or management policies to prevent installation of unauthorized/unverified extensions.
Security Awareness
- Consider training users to recognize ClickFix-style social engineering prompts that instruct them to manually run PowerShell or paste commands.
- Consider educating users to validate the source website and vendor before downloading and executing any new software, especially fake update prompts.
- Consider raising awareness among cryptocurrency wallet users about fake GUI recovery-seed prompts and the importance of never entering seed phrases into unsolicited desktop applications.
- Consider incorporating guidance on verifying browser extension legitimacy (publisher, permissions, reviews) into security awareness materials.
MITRE ATT&CK Mapping
Initial Access
Execution
Persistence
Privilege Escalation
Stealth
Defense Impairment
Credential Access
Command and Control
Additional IOCs
- Ips:
91[.]92[.]33[[.]]167- Lobshot C2 server in the Urutyka campaign94[.]26[.]90[[.]]112- Callback server for traffic1.exe delivery in Garrigin campaign216[.]107[.]139[[.]]188- CastleStealer C2 for strainted[.]com in Noidret campaign151[.]240[.]151[[.]]126- Callback server for traffic1.msi delivery
- Domains:
pub-6728b11f74fd435f926ed25c5f2952bb[[.]]r2[[.]]dev- Cloudflare R2 CDN used to host traffic1.msi download in Urutyka campaigngoodbytetelegramm[[.]]com- Download server used in Urutyka campaigndrrajivparti[[.]]com- NetSupport RAT C2 in Urutyka campaigneazysitebuilder[[.]]com- NetSupport RAT C2 in Urutyka campaignpub-4d5f81bf79554aa7a2187e6ffbc9702a[[.]]r2[[.]]dev- Cloudflare R2 CDN hosting traffic1.exe in Garrigin campaigngrenagana[[.]]com- Download server delivering CastleLoader Stage 2 shellcode (document1 payload) in Garrigin campaigngrorriner[[.]]com- Download server used in Garrigin campaign infrastructureebedidance[[.]]com- NetSupport RAT C2 in Garrigin campaignsocom-game[[.]]com- NetSupport RAT C2 in Garrigin campaignp-rala[[.]]com- NetSupport RAT C2 in Noidret campaignitalianhitech[[.]]com- NetSupport RAT C2 in Noidret campaignthenugcompany[[.]]org- Staged domain observed pulling new CastleLoader stagerskipraid[[.]]com- Staged domain found June 24, 2026, hosted on Cloudflareclaudenell[[.]]net- Finger domain identified June 24, 2026, likely staged infrastructureclaudettes[[.]]net- Finger domain pointing to avivtech default3, likely staged infrastructureteamsvoicepremium[[.]]com- Finger domain identified June 24, 2026, likely staged infrastructureavivtech[[.]]org- Domain observed pulling py-Castle payloads June 23-24, 2026hobtech[[.]]net- Staged domain that was not delivering payloads when queriedmonblare[[.]]com- Dormant domain hosted alongside kaneta[.]cc with no VT detections, possibly staged for future usekaneta[[.]]cc- Domain with minimal traffic possibly staged for future campaign, related to signed installer infrastructurenoidoret[[.]]com- C2 domain decrypted from ChaCha20-encrypted configuration, used for bw-base payload delivery
- Urls:
hxxps://pub-6728b11f74fd435f926ed25c5f2952bb[.]r2[.]dev/traffic1.msi- MSI download URL for stage 2 payload in Urutyka campaignhxxp://151[.]240[.]151[.]126/dl-callback/wg868z9e/traffic1.msi/- Callback URL used by PowerShell stager after MSI downloadhxxps://urutyka[.]com/473070fa-6f82-5c2a-9dee-3db4be57110f/doc1- Download URL for CastleLoader payload in Urutyka campaignhxxps://pub-4d5f81bf79554aa7a2187e6ffbc9702a[.]r2[.]dev/traffic1.exe- Cloudflare R2 download URL for fake Edge update installer in Garrigin campaignhxxp://94[.]26[.]90[.]112/dl-callback/6dkcdpd7-4jacbuf9-prutgux4-2ybssc8v/traffic1.exe/1390903f57b21f346193aefbbfd36759- Callback URL confirming successful traffic1.exe deliveryhxxps://fangorinaf[.]com/XSeKAKD322445k2i/default- Decrypted C2 URL for NetSupport RAT tasking in Noidret campaignhxxps://strainted[.]com/6d6d2d17-d270-59c6-8b75-df011af08e58/net40- Decrypted C2 URL delivering CastleStealer net40 payloadhxxps://noidoret[.]com/6d6d2d17-d270-59c6-8b75-df011af08e58/bw-base- Decrypted C2 URL delivering NeedleStealer Golang browser payloadhxxps://quiantar[.]com/KsXmmKiN5N0j/desktop-wallet.bin- Decrypted C2 URL delivering NeedleStealer Rust desktop wallet spoofer binary
- File Hashes:
0c48fd6a18ad9c701b254bbdd412efbf7dfdd2be6534a61c14bce719d259df9f(SHA256) - CastleLoader-related sample identified via YARA retrohunt, June 2026, 0 detectionsfa67487da701ce1d61ee3abb84869f669a6c2aa50ca0148a3c4a87e667716638(SHA256) - CastleLoader-related sample identified via YARA retrohunt, May 20262fcf553b9656523b3207c08cdf16f7be9a25e55cf8c29f5caf933151c9214367(SHA256) - CastleLoader-related sample identified via YARA retrohunt, March 2026edff43ecdf7aa476331d925db04e68a2251920165a2109be9df91a56d86b87c7(SHA256) - Reference sample for new shellcode loader variant contacting qxvnrta.comd26ea6828cc01ae151d99bbee78c4e6d132e9077842a558bce3901fa0970d9be(SHA256) - Signed malicious installer sample linked to kaneta.cc/monblare.com infrastructure
- Registry Keys:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU- Registry key deleted by PowerShell downloader to erase Run dialog history and cover tracks
- File Paths:
%ProgramData%\EdgeUpdate\traffic1.exe- Drop path masquerading as legitimate Windows EdgeUpdate directory in Garrigin campaignProgramData\NodeJS- Directory where NeedleStealer ZIP archive and legitimate Node.js binary are extracted%ProgramData%\Prodclear\Packages\Network- Installation path referenced in decrypted CastleLoader configurationC:\ProgramData\Zooms- Target directory used by final.ps1 PowerShell stage in Urutyka campaign~\AppData\Local\Packages\Extensions\9D3050BA117467D4446B49E071512F60FD450E4925F7747AE956DBF07CEAE04F- Local installation path of the malicious fake AdBlock browser extension used by NeedleStealer Golang payload
- Command Lines:
- Purpose: Execute embedded IronPython interpreter against an obfuscated remediation script to continue the infection chain | Tools:
ipyw32.exe,IronPython| Stage: Execution / Defense Evasion |ipyw32.exe -x <script.txt> - Purpose: Launch a hidden, bypass-policy PowerShell process to execute a dropped payload script | Tools:
powershell.exe| Stage: Execution - Purpose: Delete Run dialog MRU registry key to remove forensic evidence of manually executed commands | Tools:
reg.exe| Stage: Defense Evasion
- Purpose: Execute embedded IronPython interpreter against an obfuscated remediation script to continue the infection chain | Tools:
- Other:
bgphpngpjjpmkllibbfmamopengnfdng- Chrome extension ID for the malicious fake AdBlock extension used by NeedleStealer Golang payload