CastleStealer Malware Uses Browser Protection Bypass and Remote Shell to Expand Attacker Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


CastleStealer, an emerging C#-based information stealer, has added browser protection bypass and remote shell features that give its operators a wider path into compromised Windows systems.

The newer malware samples can collect browser data protected by Chromium’s App-Bound Encryption, run commands on a victim device, download extra payloads, and move stolen information through small encrypted network transmissions rather than one large archive.

Flashpoint’s analysis shows that the malware is becoming more capable even though it has not yet reached the broad use seen with major established stealer families.

CastleStealer was first publicly identified in April 2026 in a ClickFix campaign, where victims were tricked into running a Python script that launched CastleLoader. By June, the delivery method had changed.

Malicious Google ads led users looking for Node.js to fake installer websites, which delivered a batch file and the OXLOADER malware loader.

Cyber Security News previously reported how fake Node.js installer ads used OXLOADER to place CastleStealer in memory, making the chain harder for traditional file-based security tools to catch.

Analysts at Flashpoint identified the latest CastleStealer functions, noting that its developers have improved both what the malware can collect and what an operator can do after it reaches a device.

The change matters because an information stealer is no longer limited to collecting passwords and browser cookies before ending its work.

CastleStealer can now act as a basic remote access tool, creating a route for further malware delivery or hands-on activity on the same machine.

CastleStealer Malware Uses Browser Protection Bypass

The malware begins by checking whether the Windows Multilingual User Interface language is Russian (ru-RU). It then contacts its command-and-control server, sends its build UUID and basic device details, and collects more information about the host.

CastleStealer searches Chromium-based browsers for login data, cookies, browsing history, web data, browser-extension details, IndexedDB content, and extension storage. It also collects Firefox login data, cookies, history, and form history.

Its targets extend beyond browsers. CastleStealer searches for Steam files, including config.vdf, loginusers.vdf, and local.vdf, which may contain account details and settings.

Contents of downloaded batch script masquerading as a Node.js installer (Source - Flashpoint)
Contents of downloaded batch script masquerading as a Node.js installer (Source – Flashpoint)

It also looks in APPDATA directories linked to Discord and Telegram. The malware broadly searches local files, with special attention to filenames containing “wallet,” while excluding certain file types and files containing the word “backup.”

This focus on browser sessions, messaging applications, game accounts, and crypto-related files raises the risk of account takeover and financial theft after an infection.

The most important new feature is the bypass of Chromium App-Bound Encryption. This protection was designed to make browser cookie theft harder by tying encrypted data to the browser application and device.

Earlier CastleStealer versions could not access data from updated browsers using this safeguard. New samples use Chrome’s IElevator COM interface to bypass the protection and gain access to browser data that was previously out of reach.

The technique follows a wider trend documented in Chrome cookie protection bypasses, where stealers abuse browser elevation-related components to reach protected data.

CastleStealer’s remote shell function changes the malware from a simple data collector into a tool that can support further work on a compromised system.

Operators can send a shell command, provide a file for execution, or instruct the malware to download and run another payload from a URL.

In practical terms, this means the operator can decide what to do after reviewing the first stolen data, rather than relying only on the original malware package.

That capability can support the delivery of additional stealers, remote access tools, or other malicious programs.

It also makes quick containment more important. Security teams investigating a CastleStealer alert should treat the affected endpoint as potentially interactive, review child processes and command-line activity, isolate the device where appropriate, reset exposed browser sessions, and review authentication logs for the accounts used on that system.

Similar malware operations have shown how remote terminal data theft can combine browser collection with command execution and encrypted command-and-control traffic.

Smaller Encrypted Transfers Can Hide Activity

Instead of placing all collected information into one archive and sending it to a server or Telegram channel, CastleStealer transfers data in smaller chunks over raw TCP.

Each transmission uses AES encryption. Flashpoint said the packet structure consists of a four-byte size field, an AES initialization vector, and encrypted data.

IElevator COM CLSIDs present for various Chromium-based browsers in newer CastleStealer samples (Source - Flashpoint)
IElevator COM CLSIDs present for various Chromium-based browsers in newer CastleStealer samples (Source – Flashpoint)

This method may help the traffic blend into normal network activity by avoiding the large outbound spike often created by a single archive upload. The malware removes itself after completing its activity through a ping-delay self-deletion technique.

Defenders should therefore prioritize behavioral records such as endpoint telemetry, process trees, browser-related COM activity, suspicious outbound TCP connections, PowerShell use, and newly downloaded files.

Organizations should also warn users not to run commands from fake verification prompts, a social-engineering method explained in this ClickFix malware delivery guide.

Indicators of compromise (IoCs):-

IoC category Value from source Defensive use
SHA-256 / file hash Not published Hunt using endpoint behavior and malware family detections rather than an unverified hash.
C2 domain or IP address Not published Review unusual outbound raw TCP sessions from devices showing stealer behavior.
Download URL Not published Investigate software downloads from fake Node.js pages, sponsored search results, and untrusted sites.
Process or component Chrome IElevator COM interface Alert on unusual non-browser access patterns involving browser elevation services.
Network format {4-byte size} → {AES IV} → {Encrypted Data} Use as supporting context during packet analysis, not as a standalone signature.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post CastleStealer Malware Uses Browser Protection Bypass and Remote Shell to Expand Attacker Access appeared first on Cyber Security News.