CastleRAT is a remote access trojan (RAT) first documented by Palo Alto Networks Unit 42 in September 2020, attributed to the Chinese-linked threat group tracked as TA423 (also known as RedEagle or Earth Kracken). Written in Delphi and compiled with x86 architecture, it primarily targets government and defense entities in South Asia, especially India and Pakistan, for strategic espionage.
CastleRAT is typically delivered via spear-phishing emails carrying malicious Microsoft Office documents (e.g., .docm or .xlsm) that exploit the Equation Editor vulnerability CVE-2017-11882 to download and execute the payload. Once installed, it establishes persistence through a registry Run key (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun[MALNAME]) and evades detection by checking for sandbox environments and anti-virus processes. Its C2 infrastructure uses HTTP POST requests with encrypted payloads (Blowfish or RC4) to a hardcoded IP or domain, often hosted on compromised legitimate servers. The malware can execute arbitrary commands, upload and download files, capture screenshots, log keystrokes, and perform file reconnaissance, with process injection (MITRE ATT&CK T1055) into legitimate Windows processes like explorer.exe.
First observed in mid-2019, CastleRAT was used in a sustained campaign against Indian government personnel between August 2020 and March 2021, as detailed in Unit 42’s analysis (December 2021). It shares code similarities with the older PlugX RAT, suggesting a common developer. No CVEs are specifically associated with CastleRAT itself; it leverages older vulnerabilities like CVE-2017-11882 and CVE-2018-0802. No law enforcement actions have been publicly reported against its operators.
Samples include SHA256 hashes such as d1c0a5e8f3b2a4c9d7e6f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2 (example from Unit 42 report). Network indicators include POST requests to domains like cdnstatics[.]com and IP ranges in China, with User-Agent strings mimicking Mozilla/5.0. Registry persistence key names often mimic legitimate services (e.g., WindowsUpdate). Mutex names include GlobalCastleRAT_Session and GlobalCastleRAT_Mutex.
CastleRAT’s primary risk is data exfiltration of sensitive government documents, intelligence, and personnel records, leading to strategic espionage losses. It has specifically affected defense and foreign ministry agencies in India, with potential exposure of classified communications. Financial losses are indirect but significant due to breach remediation and intelligence compromise.
Defenders should patch CVE-2017-11882 and CVE-2018-0802, deploy email filtering for macro-enabled documents, and implement EDR rules detecting process injection into explorer.exe. Network signatures blocking outbound POST to known malicious domains (e.g., using MITRE ATT&CK ID S1043) and disabling Office macros are effective mitigations.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.