
Digitally Signed CastleLoader Installers Strip Mark-of-the-Web and Inject Payloads Into Memory
Arctic Wolf Labs has uncovered new CastleLoader campaigns using digitally signed installers, Mark-of-the-Web (MotW) removal, and in-memory shellcode injection to deliver malware. The activity expands an already active campaign cluster linked to CastleStealer, PythonRAT, NetSupport RAT, and newly observed NeedleStealer payloads. CastleLoader is a multi-stage loader commonly distributed through fake software installers, ClickFix lures, and […]
The post Digitally Signed CastleLoader Installers Strip Mark-of-the-Web and Inject Payloads Into Memory appeared first on Cyber Security News.