Cybersecurity researchers have discovered new CastleLoader malware campaigns that now deliver NeedleStealer, a malware family designed to steal cryptocurrency wallet recovery phrases, browser sessions, and user credentials. The latest activity shows that attackers are expanding their capabilities with more advanced tools and new programming languages, making these campaigns increasingly difficult to detect.
CastleLoader Continues to Evolve
CastleLoader has been active for some time as a malware loader that delivers additional malicious payloads onto compromised systems. Previous campaigns primarily distributed information stealers and remote access tools. However, recent investigations reveal that threat actors have significantly upgraded the framework by integrating NeedleStealer into their attack chain.
Researchers also observed the first use of Rust and Golang within these campaigns. Combined with in-memory execution, these technologies help attackers avoid traditional security detection while improving the malware’s flexibility.
NeedleStealer Focuses on Financial Theft
One of the most concerning additions is a Rust-based component that impersonates popular cryptocurrency wallet applications. Victims are presented with convincing recovery phrase prompts that appear legitimate. If users enter their wallet seed phrase, attackers can gain complete access to their cryptocurrency holdings.
Another component, developed in Golang, installs malicious browser extensions that appear to be legitimate software. These extensions allow attackers to hijack browser sessions and steal credentials without requiring victims to repeatedly enter their passwords.
Multiple Campaigns Using Similar Techniques
Researchers identified three related campaigns—Urutyka, Garrigin, and Noidret—that all rely on CastleLoader as the initial infection method. Although each campaign introduces slight variations, they follow a similar multi-stage approach to deliver malware while making forensic analysis more difficult.
The attackers also continue to use digitally signed installers and carefully managed command-and-control infrastructure, increasing the likelihood that the malware will bypass security defenses.
Why This Matters
The latest CastleLoader campaigns demonstrate a clear shift toward targeting high-value financial information and online accounts. Instead of simply stealing passwords, attackers are now attempting to compromise cryptocurrency wallets and active browser sessions, allowing them to bypass authentication and gain access to valuable assets.
Organizations should remain alert for suspicious PowerShell activity, unexpected browser extensions, unusual outbound network connections, and software installers from untrusted sources. Behavioral monitoring and modern endpoint protection can also help detect malware that executes directly in memory.
Conclusion
The integration of NeedleStealer marks another step in the evolution of CastleLoader. By combining multi-stage malware delivery, Rust and Golang payloads, browser session hijacking, and cryptocurrency theft, threat actors are building more sophisticated attack campaigns. As these techniques continue to evolve, organizations should strengthen endpoint security, monitor suspicious activity, and educate users about the risks of downloading software from unverified sources.