CastleLoader Malware Infects 469 Devices Using Fake GitHub Repos and ClickFix Phishing
Researchers studying cybersecurity have revealed CastleLoader, a novel and adaptable malware loader that has been used in campaigns that disseminate different types of remote access trojans (RATs) and information thieves.
According to a tip published with The Hacker News, the activity uses ClickFix phishing assaults with a Cloudflare theme and phony GitHub repositories that are opened under the names of genuine applications.
DeerStealer, RedLine, StealC, NetSupport RAT, SectopRAT, and even other loaders like Hijack Loader have all been distributed by the malware loader, which was first discovered in the wild earlier this year.
According to the corporation, it uses packing and dead code injection tactics to obstruct analysis. It first unpacks itself at runtime, then establishes a ...

