CastleStealer Malware Bypasses Chromium Protection
Chromium protection no longer serves as an insurmountable barrier for CastleStealer. New malware samples can bypass browser defenses effectively. They also provide operators with a channel for remote control over infected computers. Furthermore, Flashpoint discovered these changes while analyzing fresh versions of the software. The public first noticed this malicious program in April 2026.
Upgraded Browser Secret Theft
The primary update concerns the protection of browser secrets. Early CastleStealer variants could not extract securely encrypted data. The App-Bound Encryption mechanism previously blocked these attempts. This mechanism links the decryption of cookies and saved credentials directly to the browser. However, the malware now targets the IElevator COM interface in Chrome. Consequently, it gains access to previously unattainable information.
Upon launch, CastleStealer harvests logins, cookies, and browsing history from Chromium browsers. It also extracts web data and extension information. Meanwhile, the malware hunts for credentials, cookies, and form data within Firefox. Additionally, the program inspects Steam files alongside Discord and Telegram directories. It specifically searches documents for the word “wallet” to locate cryptocurrency assets.
Remote Execution and Covert Data Theft
New versions also feature a basic remote shell. An operator can send a system command or transfer a file for execution. Alternatively, they can specify an address for an additional payload. CastleStealer will then download and execute this payload. As a result, the infostealer transforms from a simple data theft tool. It now serves as a persistent access point to the compromised system.
The method of exfiltrating information has also evolved significantly. CastleStealer no longer sends a single massive archive. Instead, it transmits small data fragments directly via TCP. Furthermore, it encrypts this traffic using the AES standard. Each packet contains a four-byte size field, an initialization vector, and the encrypted data. According to Flashpoint, fragmenting the transmission might reduce noticeable network traffic spikes. However, the encryption itself does not render the exchange completely invisible.
Advanced Evasion Tactics
Simultaneously, the developers are complicating the delivery chain. CastleStealer spread through ClickFix and CastleLoader during the spring. Later, it appeared in a campaign featuring fake Node.js advertisements and the OXLOADER downloader. This tool decrypts its own code multiple times. It conceals API calls and checks for sandboxes before executing components in memory. Consequently, these evasion tactics severely hinder automated analysis.
Despite these functional advancements, Flashpoint has not yet observed a massive migration of threat actors to CastleStealer. Nevertheless, the malware has eliminated a significant prior limitation. It gained remote command execution capabilities and a more covert method for transmitting stolen information. Finally, the program deletes its own file upon completion using a delayed ping technique. This action effectively reduces the number of forensic artifacts left on the infected machine.









