VYPR
researchPublished Jul 28, 2026· 1 source

CastleLoader Campaign Evolves to Target Crypto Users with Fake Wallets and Browser Extensions

The CastleLoader campaign has expanded its arsenal to include sophisticated tools designed to steal cryptocurrency recovery phrases and browser sessions through fake wallet interfaces and malicious browser extensions.

The CastleLoader campaign, a persistent threat actor known for its evolving tactics, has launched a new wave of attacks specifically targeting cryptocurrency users. Recent analysis by Arctic Wolf reveals that attackers are employing highly convincing fake cryptocurrency wallet screens and malicious browser extensions to steal recovery phrases, login credentials, and active browser sessions. This evolution signifies a shift from general credential theft to more specialized and high-value targets within the digital asset space.

The operation typically begins with social engineering tactics, such as fake software installers and "ClickFix"-style prompts that trick victims into executing malicious PowerShell commands. Once initiated, the CastleLoader can download and execute further malware payloads without leaving easily detectable files on the system, complicating initial detection efforts. Arctic Wolf has identified these new payloads while tracking various CastleLoader clusters, including Urutyka, Garrigin, and Noidret, indicating a coordinated and ongoing effort.

A particularly concerning development is the introduction of a Rust-based "NeedleStealer" wallet spoofer. This tool presents a polished imitation of legitimate desktop wallet applications from brands like Ledger, Trezor, and Exodus. Its primary goal is to trick users into entering their recovery seed phrase into the fake interface, granting attackers complete and permanent control over the victim's cryptocurrency wallet. The spoofer is often delivered via a Node.js-based injector and a shellcode component, blending in with normal system activity by residing alongside legitimate Node.js binaries.

Beyond wallet spoofing, the campaign also leverages Golang-based malicious browser extensions. These extensions masquerade as legitimate software, such as ad blockers, while secretly harvesting sensitive browser data, including active session tokens. Stealing a session token can be more damaging than obtaining a password, as it allows attackers to bypass multi-factor authentication and gain immediate access to accounts without requiring further verification.

The reliance on recovery phrases for wallet theft is a critical vulnerability, as these phrases cannot be reset like passwords. Attackers exploit this by creating an illusion of trust through familiar interfaces and social engineering prompts. Users are often coerced into running commands or visiting fake update pages, mirroring tactics seen in previous information-stealing campaigns.

Defensive measures recommended by Arctic Wolf include blocking malicious infrastructure at the DNS and firewall layers, and treating unusual PowerShell, IronPython, Node.js, or Python activity originating from user-writable directories as a significant warning sign. Organizations should also implement application allowlisting, monitor for unauthorized changes to browser extensions, and educate users about the dangers of executing commands from untrusted sources.

This expansion of CastleLoader's capabilities highlights the increasing sophistication of threat actors targeting the cryptocurrency ecosystem. The combination of convincing social engineering, fileless malware delivery, and specialized tools for stealing recovery phrases and session tokens presents a formidable challenge for both individual users and organizations managing digital assets.

Synthesized by Vypr AI