CastleStealer Malware Evolves with Browser Protection Bypass and Remote Shell Capabilities
CastleStealer, a C#-based information stealer, now bypasses Chromium's App-Bound Encryption and includes a remote shell, expanding its threat beyond credential theft.

CastleStealer, an information-stealing malware family written in C#, has recently incorporated significant new features, including the ability to bypass Chromium's App-Bound Encryption and the addition of a remote shell function. These enhancements allow attackers to gain deeper access to compromised Windows systems, steal protected browser data, execute arbitrary commands, download additional malicious payloads, and exfiltrate stolen information via encrypted network transmissions.
First identified in April 2026, CastleStealer has undergone rapid development. Initial delivery methods evolved from a ClickFix campaign to malicious Google ads leading users to fake installer websites that deployed the OXLOADER malware loader. Cyber Security News previously reported on how these fake Node.js installer ads used OXLOADER to inject CastleStealer directly into memory, evading traditional file-based security solutions.
Analysis by Flashpoint reveals that the malware's developers have improved both its data collection capabilities and the post-infection actions an operator can perform. This evolution transforms CastleStealer from a simple data collector into a more versatile tool capable of acting as a basic remote access trojan (RAT). This expanded functionality opens pathways for further malware deployment or direct hands-on activity by attackers on the compromised machine.
The malware begins its operation by checking the system's language settings for Russian (ru-RU) before communicating with its command-and-control (C2) server. It sends its build UUID and basic device information, then proceeds to gather more host details. CastleStealer targets sensitive data within Chromium-based browsers, including login credentials, cookies, browsing history, and IndexedDB content. It also targets Firefox data and extends its reach to Steam files, Discord and Telegram configurations, and broadly searches for files containing the term "wallet," indicating a focus on financial and account takeover threats.
A key advancement is CastleStealer's ability to bypass Chromium's App-Bound Encryption, a security measure designed to protect browser cookies from theft. By exploiting Chrome's IElevator COM interface, the malware can now access browser data that was previously inaccessible, aligning with a broader trend of stealers abusing browser elevation components.
The newly added remote shell function significantly enhances CastleStealer's utility. Operators can now send shell commands, provide files for execution on the victim's system, or instruct the malware to download and run additional payloads from a specified URL. This allows for dynamic response and further compromise based on the initial data exfiltrated, making rapid containment crucial for affected organizations.
To evade detection, CastleStealer transfers collected data in small, AES-encrypted chunks over raw TCP, rather than a single large archive. This method helps the network traffic blend in with normal activity, making it harder for security tools to identify. The malware also employs a ping-delay self-deletion technique to remove itself after completing its tasks, emphasizing the importance of monitoring behavioral indicators like endpoint telemetry and suspicious network connections.
Security teams investigating CastleStealer infections should treat affected endpoints as potentially interactive. Recommended actions include reviewing child processes and command-line activity, isolating devices, resetting exposed browser sessions, and scrutinizing authentication logs for compromised accounts. The malware's ability to combine browser data theft with command execution and encrypted C2 traffic presents a significant, evolving threat.