Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > CastleStealer Malware Adds Remote Shell Access After Cracking Chrome’s Cookie Protection
CastleStealer Malware Adds Remote Shell Access After Cracking Chrome’s Cookie Protection
Read Time:3 Minute, 31 Second

A relatively young Windows information stealer called CastleStealer has picked up a pair of capabilities that push it well beyond typical credential theft. New samples analyzed by threat intelligence firm Flashpoint can now bypass Chrome’s hardened cookie protection and give an attacker an interactive remote shell on the infected machine — turning a data-grabbing tool into a foothold for further intrusion.

From ClickFix Scripts to Fake Node.js Installers

CastleStealer, written in C#, was first publicly identified in April 2026 as part of a ClickFix campaign, where victims were tricked into pasting and running a Python script that launched a loader known as CastleLoader. By June, the delivery method had shifted: malicious search ads targeting people looking for Node.js led to fake installer pages that dropped a batch file and a separate loader called OXLOADER, which placed CastleStealer directly into memory rather than onto disk.

That memory-resident approach already made the chain harder for traditional file-scanning security tools to catch. The malware’s newest functions make detection and containment harder still.

Breaking Chrome’s App-Bound Encryption

Chrome’s App-Bound Encryption was designed specifically to blunt cookie and credential theft by tying encrypted browser data to the Chrome application and the device it runs on, a defense that had previously locked earlier CastleStealer builds out of updated browsers. New samples defeat this by abusing Chrome’s IElevator COM interface, a legitimate browser component, to reach data that should otherwise be inaccessible to an outside process.

With that barrier cleared, CastleStealer can pull login data, cookies, browsing history, extension storage, and IndexedDB content from Chromium-based browsers, along with equivalent data from Firefox. It doesn’t stop at browsers: the malware also hunts for Steam configuration files that can hold account details, scans Discord and Telegram application-data folders, and broadly searches local storage for anything with “wallet” in the filename, while deliberately skipping files it suspects are backups.

A Remote Shell Changes the Calculus

The more consequential addition is a built-in remote shell. Operators can now issue direct shell commands, push a file to the victim machine for execution, or instruct the malware to fetch and run an entirely new payload from a URL. That turns CastleStealer from a one-shot data collector into a live access point: an attacker can review what was stolen first, then decide in real time whether to deploy additional malware or take hands-on action on that specific machine.

For defenders, that distinction matters enormously. A CastleStealer alert should now be treated as a potential interactive-intrusion event rather than a routine stealer cleanup, with analysts reviewing child processes and command-line history, isolating the endpoint where feasible, and resetting any browser sessions and credentials exposed on that device.

Smaller, Encrypted Transfers Instead of One Big Upload

CastleStealer has also changed how it moves stolen data off the host. Rather than bundling everything into a single archive and uploading it in one burst — the kind of traffic spike many network monitoring tools are tuned to catch — it now sends data over raw TCP in small AES-encrypted chunks, each wrapped in a compact structure consisting of a size field, an initialization vector, and the encrypted payload itself. Spreading the exfiltration across many small transmissions helps the traffic blend into ordinary network noise. Once its work is finished, the malware removes itself using a delayed self-deletion technique.

What Security Teams Should Watch For

  • Unusual non-browser processes interacting with Chrome’s IElevator COM interface.
  • Suspicious outbound raw TCP sessions, particularly small, repeated, encrypted transmissions rather than a single large upload.
  • Software downloads originating from fake Node.js installer pages, sponsored search results, or otherwise untrusted sites.
  • PowerShell or batch-script execution tied to ClickFix-style “verification” prompts that ask users to paste and run commands.

Flashpoint notes CastleStealer hasn’t reached the scale of established stealer families yet, but its rapid feature growth — particularly the shift toward remote interactivity — suggests its operators are actively investing in the tool. Organizations should treat any confirmed infection as a potential launchpad for a secondary payload, not an isolated credential-theft incident, and should train users to recognize and refuse “copy this command and run it” prompts regardless of how official the surrounding page looks.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on CastleStealer Malware Adds Remote Shell Access After Cracking Chrome’s Cookie Protection, use the discussion on Forum.

>> forum community

Comments

Leave a Reply