Red Canary's July 2026 threat intelligence report highlights ClearFake as the top prevalent threat for the third consecutive month, using fake CAPTCHA lures on compromised websites for paste and run malware delivery. CastleLoader debuts in the top 10, distributed via fake background removal sites and job platform impersonation domains, employing a Bring-Your-Own-Interpreter technique with portable Python distributions to execute triple-layer encoded shellcode loaders that inject the CastleLoader binary into python.exe. KongTuke TDS saw significant activity increase, using compromised WordPress sites and caret-obfuscated curl commands to .top domains for initial execution.
CastleLoader
7 posts
Intelligence Insights: July 2026 Expanding the Castle: New Campaigns, New Tooling, and the NeedleStealer Connection Arctic Wolf Labs tracked an expanding CastleLoader delivery cluster (Urutyka, Garrigin, Noidret campaigns) that uses obfuscated PowerShell stagers, embedded IronPython runtimes, and NSIS/NodeJS-based shellcode injectors to deploy CastleStealer, NetSupport RAT, Lobshot, and now NeedleStealer. NeedleStealer's newly observed Rust-based cryptocurrency wallet spoofer and Golang-based malicious browser extension installer represent a tactical shift toward high-value crypto targeting and persistent browser-layer access, delivered via digitally signed installers using fraudulently obtained code-signing certificates.
ClickFix Removes Your Background but Leaves the Malware A ClickFix social engineering campaign tricks users into executing a malicious command via a fake CAPTCHA on fraudulent background removal websites. This command uses the legacy finger.exe utility to download CastleLoader, an advanced Python-based loader that employs reflective PE loading and API evasion (such as ReplaceTextW hooking) to deploy NetSupport RAT and a custom .NET stealer (CastleStealer) for credential and data exfiltration.
2025 Year in Review: Malicious Infrastructure In 2025, Insikt Group observed the continued dominance of Cobalt Strike, AsyncRAT, and infostealers like Vidar, alongside the rise of new offensive tools such as RedGuard, Ligolo, and CastleLoader. The report highlights the critical role of Threat Activity Enablers (TAEs) and the abuse of legitimate infrastructure services, such as CDNs, in sustaining cybercriminal and APT operations.
2025 Identity Threat Landscape Report The 2025 Identity Threat Landscape Report highlights a massive surge in credential theft driven by infostealer malware, with LummaC2 leading the ecosystem. A critical finding is the widespread theft of active session cookies, which allows attackers to bypass multi-factor authentication (MFA) and directly access high-value corporate systems, VPNs, and cloud platforms.
Iranian MOIS Actors & the Cyber Crime Connection Iranian Ministry of Intelligence and Security (MOIS) affiliated threat actors, including Void Manticore and MuddyWater, are increasingly integrating cybercriminal tools, infrastructure, and affiliate models into their operations. This strategic shift, which includes the use of commercial infostealers like Rhadamanthys and RaaS platforms like Qilin, enhances their operational capabilities while complicating attribution efforts.
- 6 minWeekly Recap — 2026-04-27 -> 2026-05-04
AI Weaponization and Developer Supply Chain Attacks Redefine the Perimeter Attackers are aggressively targeting the software development process because compromising a single developer tool can unlock thousands of corporate networks. In parallel, artificial intelligence is collapsing the cost of attacks, allowing criminals to build convincing deepfakes and automated phishing campaigns in minutes. As a result, traditional security like multi-factor authentication is increasingly bypassed using tricks that steal active login sessions rather than passwords. These trends together suggest that relying on perimeter defenses and basic hygiene is no longer enough, as attackers hide inside trusted cloud services and legitimate software updates. This matters because organizations are losing visibility into where their sensitive data actually lives, especially as AI tools create hidden pathways into company systems. Defenders must shift their focus to monitoring user behavior after login and securing the automated systems that build their software. Watch for unusual activity in your developer tools and implement stricter checks on third-party software.