CastleStealer now bypasses Chrome app-bound encryption through the IElevator COM interface. https://intel.threadlinqs.com/threat/TL-2026-3056 #ThreatIntel #CastleStealer #OXLOADER #CASTLELOADER

CastleStealer now bypasses Chrome app-bound encryption through the IElevator COM interface. https://intel.threadlinqs.com/threat/TL-2026-3056 #ThreatIntel #CastleStealer #OXLOADER #CASTLELOADER
CastleLoader tricks you into pasting your own malware, then hides inside a Python interpreter to inject it. https://intel.threadlinqs.com/threat/TL-2026-2589 #ThreatIntel #CASTLELOADER #NightshadeC2 #NetSupportManager
SloppyRAT abuses the ancient Finger protocol to drop a RAT with blockchain-based C2 fallback. https://intel.threadlinqs.com/threat/TL-2026-2439 #ThreatIntel #CASTLELOADER #NightshadeC2 #SloppyRAT