2026-08-23NOTABLEDead-drop C2 moved from novelty to routine, and the control is an egress baseline rather than a blocklist
CastleRAT
malware · malware:castlerat single-source
Remote-access trojan in Python and C variants providing keylogging, screen capture and remote shell, delivered via CastleLoader and ClearFake precursors and resolving a dead drop through a public community profile or adversary-controlled domains (Red Canary, 2026-08-20).
Coverage
1
first 2026-08-23 → last 2026-08-23
Latest activity
2026-08-23
Dead-drop C2 moved from novelty to routine, and the control is an egress baseline rather than a blocklist
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, finance, telco · regions: europe
Sources cited
1
1 hosts
Action items (1)
Do-now tasks recorded on the entries about CastleRAT, newest first. Check the date before acting on an older one.
- Establish which users, systems and applications in your estate legitimately make HTTPS calls to public blockchain RPC endpoints (for most public-sector estates the honest answer is none) and alert on anything outside that set; chainlist.org enumerates the widely-used endpoints adversaries prefer.2026-08-23Dead-drop C2 moved from novelty to routine, and the…
Defender insights
What each entry about CastleRAT tells a defender to do, newest first.
Triage
Story timeline
ATT&CK techniques (5 across 6 tactics)
5 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ExecutionUser Execution: Malicious Copy and Paste
- PersistenceCreate or Modify System Process: Launch Agent · Modify Authentication Process: Multi-Factor Authentication
- Privilege EscalationCreate or Modify System Process: Launch Agent
- Defense ImpairmentModify Authentication Process: Multi-Factor Authentication
- Credential AccessSteal Application Access Token · Modify Authentication Process: Multi-Factor Authentication
- Command and ControlWeb Service: Dead Drop Resolver
Execution TA0002
T1204.004User Execution: Malicious Copy and Paste×1
An adversary may rely upon a user copying and pasting code in order to gain execution. Users may be subjected to social engineering to get them to copy and paste code directly into a Command and Scripting Interpreter. One such strategy is "ClickFix," in which adversaries present users with seemingly helpful solutions (such as prompts to fix errors or complete CAPTCHAs) that instead instruct the user to copy and paste malicious code.
Evidence: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · ATT&CK page ↗
Persistence TA0003
T1543.001Create or Modify System Process: Launch Agent×1
Adversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence. When a user logs in, a per-user launchd process is started which loads the parameters for each launch-on-demand user agent from the property list (.plist) file found in <code>/System/Library/LaunchAgents</code>, <code>/Library/LaunchAgents</code>, and <code>~/Library/LaunchAgents</code>. Property list files use the <code>Label</code>, <code>ProgramArguments </code>, and <code>RunAtLoad</code> keys to identify the Launch Agent's name, executable location, and execution time. Launch Agents are often installed to perform updates to programs, launch user specified programs at login, or to conduct other developer tasks.
Evidence: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · ATT&CK page ↗
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · ATT&CK page ↗
Privilege Escalation TA0004
T1543.001Create or Modify System Process: Launch Agent×1
Adversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence. When a user logs in, a per-user launchd process is started which loads the parameters for each launch-on-demand user agent from the property list (.plist) file found in <code>/System/Library/LaunchAgents</code>, <code>/Library/LaunchAgents</code>, and <code>~/Library/LaunchAgents</code>. Property list files use the <code>Label</code>, <code>ProgramArguments </code>, and <code>RunAtLoad</code> keys to identify the Launch Agent's name, executable location, and execution time. Launch Agents are often installed to perform updates to programs, launch user specified programs at login, or to conduct other developer tasks.
Evidence: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · ATT&CK page ↗
Defense Impairment TA0112
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · ATT&CK page ↗
Credential Access TA0006
T1528Steal Application Access Token×1
Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.
Evidence: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · ATT&CK page ↗
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · ATT&CK page ↗
Command and Control TA0011
T1102.001Web Service: Dead Drop Resolver×1
Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.
Evidence: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · ATT&CK page ↗
Entries about CastleRAT (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- redcanary.com1 (100%)