Automatically translated.View original post

CastleRAT malware attacks Windows users secretly controlling

CastleRAT malware attacks Windows users secretly controlling the machine silently.

One type of malware that many readers will be familiar with: the remote access trojan type of malware, many of which have been reborn almost every day, and this is another new one to trouble Windows users again.

According to a report by the website Cyber Security News, a new RAT type of malware called CastleRAT was detected by a research team from Splunk, an expert company building enterprise cybersecurity tools. The research team first detected this malware in March. The malware will focus on attacks on Windows users by this malware. In addition to its basic capabilities, it allows hackers to take over the victim's machine. The malware is also divided into two versions:

Python version, which is a small (Lightweight) version.

Version C is a version that comes with high-level capabilities such as Keystoke, Screen Log Stealth, and Superior Persistance.

The research team has not identified any form of proliferation or deception for hackers to download and install malware. It is technically specified that the malware, after installing itself on the system, will collect systemic information from the victim's machine, such as computer name, user name, GUID number, IP address number, etc. The malware will send it back to a C2 (Command and Control) server with fixed-line encryption (Hardcoding) after the hacker has received the information. It will send a command through the C2 server to command the malware to run in the next step.

One of the more interesting features is the Clipboard theft feature to steal sensitive data copied by the victim on the Clipboard, such as the address of sending or receiving Kryptokerrency money, passwords, to the Kryptokerrency wallet loan code, where the malware takes over Hijacking and secretly uses the Paste command and then quietly smuggles the Exfiltration back to the C2 server.

The secret to silently smuggling is that instead of the malware running a network Sockets channel that is open or even running a network API that is vulnerable to detection, the malware copies the data on the Clipboard and uses the SendInput () function to place messages on unsuspecting applications to deceive the detection system and then distributes them to the C2 server. The research team also revealed examples of this function code:

If (OpenClipboard (0164))

{

EmptyClipboard ();

HMM = GlobalAlloc (0x2000u, v2 + 1);

Dest = GlobalLock (hMem);

Strcpy (Dest, Source);

SetClipboardData (1u, hMem);

CloseClipboard ();

pInputs [0] .ki.wVk = VK _ CONTROL;

pInputs [2] .ki.wVk = 'V';

SendInput (4u, pInputs, 40);

}

In defense, the research team recommended that enterprise users regularly monitor the behavior of their network in order to prevent and intervene when they are detected.

# Recap 2025 # Take care of yourself # Open budget # Includes IT matters # Trending

2025/12/24 Edited to

... Read moreหลังจากได้รู้จักกับ CastleRAT ซึ่งเป็นมัลแวร์ในกลุ่ม Remote Access Trojan ที่มุ่งเป้าโจมตีผู้ใช้งาน Windows โดยสามารถขโมยข้อมูลที่อยู่ใน Clipboard ซึ่งเป็นข้อมูลส่วนตัวที่เราอาจคัดลอกไว้ เช่น รหัสผ่าน หรือที่อยู่คริปโตเคอร์เรนซี ผมขอแชร์ประสบการณ์และข้อควรระวังเพิ่มเติมสำหรับผู้ใช้งานทั่วไปและองค์กรครับ 1. ตรวจสอบและอัปเดตระบบเสมอ จากที่ผมติดตามข่าว พบว่าการมีระบบปฏิบัติการ Windows ที่ได้รับการอัปเดตล่าสุด จะช่วยลดช่องโหว่ที่มัลแวร์ใช้โจมตีได้พอสมควร 2. ใช้ซอฟต์แวร์แอนตี้ไวรัสและโปรแกรมความปลอดภัยที่น่าเชื่อถือ สาเหตุที่ CastleRAT ใช้โค้ดที่ส่งคำสั่งผ่านฟังก์ชัน SendInput() เพื่อหลอกระบบตรวจจับเป็นเทคนิคที่ฉลาดมาก ผู้ใช้ควรติดตั้งซอฟต์แวร์ที่สามารถตรวจจับพฤติกรรมที่ไม่ปกติในระบบ 3. ระวังการดาวน์โหลดไฟล์หรือคลิกลิงก์จากแหล่งที่ไม่น่าเชื่อถือ เนื่องจากทีมวิจัยไม่ได้ระบุชัดเจนวิธีแพร่กระจายของ CastleRAT แต่โดยปกติมัลแวร์ประเภท RAT มักใช้วิธีนี้ 4. อย่าคัดลอกข้อมูลสำคัญลง clipboard โดยไม่จำเป็น เลี่ยงการเก็บข้อมูลสำคัญบน clipboard นานเกินไป และล้าง clipboard หลังใช้งาน เช่น รหัสผ่านหรือที่อยู่กระเป๋าเงินคริปโต 5. สำหรับองค์กร ควรตั้งระบบเฝ้าระวังพฤติกรรมเครือข่าย และวิเคราะห์ log การใช้งานอย่างสม่ำเสมอ เพื่อพบความผิดปกติที่อาจเกิดจาก RAT จาก OCR โค้ดที่ทางทีมวิจัยเปิดเผย ช่วยให้เราเห็นภาพว่ามัลแวร์ใช้งานฟังก์ชันของ Windows API ในการจัดการ clipboard อย่างไร นี่เป็นเคล็ดลับของ CastleRAT ที่ทำให้ยากต่อการตรวจจับและแอบส่งข้อมูลออกไปยังเซิร์ฟเวอร์แฮกเกอร์ ท้ายที่สุด การรับรู้และเข้าใจพฤติกรรมของมัลแวร์ชนิดนี้จะช่วยให้เราปรับตัวและป้องกันภัยไซเบอร์ได้ดีขึ้น รักษาความปลอดภัยข้อมูลส่วนตัวเป็นเรื่องสำคัญที่ไม่ควรมองข้ามในยุคนี้ครับ

Related posts

It's no secret that Karol G just slayed the #Grammys #Glambot . #AwardsSeason
user6854050772614

user6854050772614

7 likes

Part 2 Trump PANICS as SPECIAL FORCES Enter WAR!!! #news #trump #politics #special #fyp
KatieCouric**

KatieCouric**

0 likes

A human brain rests on an open book, with 'Med Surg Neuro (Part 1)' text. The image serves as a cover for a nursing study guide on the nervous system, featuring the Lemon8 logo.
This page provides an overview of the nervous system, detailing the CNS and PNS, different brain parts, somatic nervous system (sensory/motor neurons), and autonomic nervous system (sympathetic/parasympathetic) with memory tricks.
This page details neuro assessment, including the Glasgow Coma Scale, orientation, posturing (decorticate, decerebrate), levels of consciousness, pupil assessment (PERRLA), deep tendon reflexes, and Babinski reflex.
All Things Nervous System! 
(Part 1)
Med Surg Neuro Week: All Things Nervous System! (Part 1) This week is all about diving deep into Neuro for nursing students! Get ready for comprehensive notes and study tips on: ✨ Nervous System Overview ✨ Neuro Assessment & Key Findings ✨ Cranial Nerves Simplified ✨ Conditions: ALS, A
JustMe

JustMe

178 likes

#TikTokCreatorSearchInsightsIncentive #narcissisticabuse #narcabuse #narcissim
Nina Batista

Nina Batista

17 likes

A Ben 10 gym audio for you. #fyp #gym #ben10 #ben10omniverse #audio
IzzyywiththeZ

IzzyywiththeZ

0 likes

Check out this website that helps you when you’re feeling uninspired! I walk you thru the process of downloading the svg file to taking it to cricut design space! Happy crafting. #designinspo #creativeart #cricutprojects #svgfiles #CricutTips
VlunaWorks

VlunaWorks

38 likes

You need TikTok ?
Here is how you can download TikTok if you need help with and apple phone just ask me I can help with Apple phone you need to change your region on the Apple Pay store
Ali

Ali

10 likes

Me as a Kpop idol | Pros & Cons
| P.s. This is made for run and under my opinions. If you don't like it, don't read it! | 1. Pro - Great singer and dancer For as long as I can remember, I've been singing and dancing since I was born. It was my passion by then and always will be. I practiced a lot when I was y
Nars

Nars

274 likes

How I cope with anxiety & panic attacks
Honestly I could go on forever with helpful tips and tricks! As someone who has struggled with anxiety I know how hard some days can be. How do you cope?❤️ #HealthTips #Lemon8Diary #fyp #anxiety #relatable #trending
Soph 🧶

Soph 🧶

40 likes

SOS!!! Wha do you do if you click a phishing email link… two times?!? So far I have: 1, added two factor sign on 2, changed my passwords 3, stress cried and spiraled But for real. What do you do… how do I know if there is now malware (? Is that what it’s called ?) living on my computer?!?
Alexandra Wildeson

Alexandra Wildeson

2 likes

An infographic titled 'ANXIETY' defines anxiety as a feeling of fear and dread. It details six types of anxiety disorders: General, Panic, Phobia-related, Separation, Selective Mutism, and Social Anxiety. The graphic also lists common symptoms like nervousness, rapid heart rate, hyperventilation, sweating, and trouble sleeping.
🤔Anxiety- What is it??
1. So what is anxiety? 2. There are different types?? 3. What does it feel like??? 🩷This document will give you the basic understanding of anxiety, the different types, and how it can make you feel. Stay strong and remember you are NOT ALONE!! Approximately 40 MILLION people suffer from anxiet
❤️ StephanieD🪽

❤️ StephanieD🪽

226 likes

Post, I found on LinkedIn learning
Here are a few posts that I have found on LinkedIn learning that I thought was helpful to myself that I wanted to share with you guys because it may help somebody else out #finds
Shaniqua Babino

Shaniqua Babino

989 likes

📍USB Write Protected? Fix It Instantly
Seeing “The disk is write-protected” error on your USB drive? This quick guide shows how to remove write protection and regain full access to your files. Learn how to check the physical lock switch, use DiskPart commands, repair file system errors, and fix registry issues step by step. Many cases a
XanthusTechCore

XanthusTechCore

5 likes

+it’s less than 80$✨❗️LINK for this item in my bio❗️
Details⬇️: This flip phone smartphone with a flip keyboard design, offering both the convenience of a traditional keypad and the functionality of a modern touchscreen device. With 4GB of internal storage, you'll have plenty of space for apps, photos, and more. The compact 3.5" displa
Atlas

Atlas

443 likes

Knife based self defense...
E.D.G.E. Knife Defense—A step-by-step program. This sensitivity work appears in Video 3 on Patreon This knife self defense course - https://www.patreon.com/posts/e-d-g-e-program-105533830 #knifedefense #selfdefense #filipinomartialarts #martialarts #martialart
RonKosakowski_TFW_PSDTC

RonKosakowski_TFW_PSDTC

0 likes

I wasn’t planning on making this.. but HISTORY ISN’T A MEME, and it isn’t a vibe! CONTEXT MATTERS! OH..and, If we’re going to make comparisons, we need to understand what we’re actually talking about— and why these patterns F-ING MATTER‼️ #PoliticalTikTok #GenZForChange #FYP #ourlifeintherain
Reality: Our Life In The 🌈

Reality: Our Life In The 🌈

3 likes

🚨 16 Billion passwords leaked - the largest breach ever 🚨 Here is how it happened and what you can do to be safe. #news #databreach #cybersecuritytips #onlinesafety
Cybersecurity Girl

Cybersecurity Girl

100 likes

😫 Wanting to quit your 9-5?
Becoming a Pinterest Manager might be for you! In less than a year, I went from earning $2K at my 9-5 to over $4K/month with Pinterest management alone. Now, with all the different skills and platforms I lesrned, I make anywhere from $12-15K A MONTH! Back then, I knew I had to do something
Bria | Social, Design, & AI

Bria | Social, Design, & AI

482 likes

Wait, is *that* why you're stuck? 🤯 This perspective on recruiting is next-level psychology! Ever considered that your *physical* reaction to your very first 'no' in network marketing is still controlling your entire present paradigm? We're talking about digging into that initial experience—was it
StaneciaGraham

StaneciaGraham

1 like

Developing a career in cybersecurity
Hey All! 👋 Want to stay safe online and protect your data? Cybersecurity knowledge is essential. It helps you secure your personal information and understand how to safeguard your digital footprint. Let’s dive into why it’s crucial! 💻🔒 Why Cybersecurity Matters Cybersecurity is about protecting
Meghana

Meghana

548 likes

#podcast #podcastclips #tools #fyp #diy #satisfying #story #relaxingvideos #nba
Kalani Vesey

Kalani Vesey

0 likes

THE HASHTAGS ARE FOR ATTENTION! COMMENT YOUR FAVE FLAVOR OF JUICE OR SOMETHING! #wlw #techtok #blacktechtok #fyp
Bre’ 🍉🇨🇩🇵🇸

Bre’ 🍉🇨🇩🇵🇸

2 likes

You Won’t Expect This
You Won’t Expect This #thenewearth #newearth #earth #multidoimensional #dimension
Smooth DoubleB

Smooth DoubleB

0 likes

A black journal featuring a white drawing of Jack Skellington's face and stars, held by a hand.
A journal spread featuring handwritten lyrics for "Sally's Song" from The Nightmare Before Christmas, adorned with various character stickers from the movie.
A journal spread with religious quotes and Bible verses about hope, rejoice, and faith, decorated with cross stickers and floral designs.
Journal Spreads ive done recently
okay its been a few months but so far i did great with all the stickers i love buyings stickers now as a comfort thing idk how to say it ig? but overall my journal spreads look so good so far i hope yall like it js as much as i do<3 anywho im waiting for an upcoming concert to add i cant wait to
mal<3

mal<3

162 likes

Cannot Upgrade to Windows 11? TPM 2.0 Not Enabled?
Having trouble upgrading to Windows 11 because TPM 2.0 isn’t enabled? 🤔 Don’t worry — I’ll show you how to check and enable TPM 2.0 step by step, so you can upgrade smoothly! #TechTips #windows #AskLemon8 #windows 11 #windows10
Moon Bureau

Moon Bureau

1 like

I have had generalized anxiety disorder since I was 10 years old. I have been to therapists I have been to acupressurist. I have seen all natural alternatives to relieving and dealing with panic attacks and anxiety. Mine was due to a huge life change that happened to me at the time and ever since t
AshTooTrippy👽🖤

AshTooTrippy👽🖤

1 like

✨ Stand out during the holidays with this combo!
Tonight's combo is one that will make you stand out. Key notes: Honey, vanilla, amber. With a light hint of tobacco. 💌 Brand: @TheTipsyGoatSoapCompany Honey Toffee 💌 Brand: @Jebouri | Arabian Perfumery honey amber 💌 Brand: @Guerlain Tobacco Honey #عطر #عطور #perfumetiktok #
✨it's malware✨

✨it's malware✨

1 like

Breathing Exercises to Help with Panic Attacks!!
In this short I talk about how breathing exercises can be a secret weapon against panic attacks. By controlling your breath, you can tell your body to 'chill out' and reduce symptoms like a racing heart. The 4-7-8 technique and box breathing are highlighted as effective methods to incre
💕 Gadde 💕

💕 Gadde 💕

3 likes

Why I switched to taking notes on my iPad
I used to love writing in notebooks, but after switching to my iPad, I can confidently say I’m never going back! Here’s why: ✨ Cuter Notes – Let’s be real…aesthetic notes make studying more enjoyable! I can use custom colors, cute stickers, and different handwriting styles to make my notes visua
Rebecca R.

Rebecca R.

262 likes

Top Cybersecurity Certificates
There are several reputable cybersecurity certifications that can help you advance your skills and knowledge in the field of cybersecurity. 1. Certified Information Systems Security Professional (CISSP): - CISSP is a globally recognized certification that covers a wide range of cybersecurit
anjali.gama

anjali.gama

110 likes

Recover Hidden Files from USB Using Command Prompt
Can’t see your files on a USB stick even though they’re there? This video shows how to use Command Prompt commands (like attrib) to unhide files hidden by system attributes or viruses — plus what to try if that doesn’t work. #USB #cmdanks #windows 11 #techtutorial #newonlemon8
XanthusTechCore

XanthusTechCore

2 likes

If you’re staring at Cricut Design Space with zero ideas this is for you! This free SVG website is perfect when you need inspiration fast. Save & share with your crafty bestie 💖 #designinspo #creativeart #DesignProcess #cricutprojects #CricutTutorial
VlunaWorks

VlunaWorks

1 like

Replying to @suad adam What is Lupus? #lupuswarrior🦋💜 #sle #lupus #autoimmunedisease #chronicillness
Heather - Living with Lupus 🦋

Heather - Living with Lupus 🦋

3 likes

In this img, I strip back the layers of a malware
STOP installing random .exe files! 🛑 This 'Physics Simulator' is actually malware in disguise. See how it hooks your keyboard in the background. Tag a friend who downloads too many mods. #cybersecurity #scamalert #keylogger
ShadowRoot17

ShadowRoot17

1 like

Back Up Outlook Emails to an External Hard Drive
Need to back up your Outlook emails to an external hard drive? Here are 2 simple methods to help you out. Download AOMEI Backupper and give it a try! #backup #outlook #externalharddrive
SmoothTechie

SmoothTechie

1 like

The #Python Foundation turned down a $1.5m grant from #nsf so they could continue to support #DEI . Please make sure to go support python.org so they can continue to do great things.
Bentley Hensel

Bentley Hensel

9 likes

“Is Varang creating followers…or controlling them?” #movies #videos #film #fouryou #avatar
MonkeyNick6

MonkeyNick6

2 likes

How to control anxiety or panic attacks 🙏
I’ve been having a really hard time of convincing myself that I may have a bad habit of controlling my anxiety. Please help a girly out! It might be more than just anxiety because of past trauma but any advice would do. #helpagirlout #anxietycontrol #advice
Janel Williams

Janel Williams

19 likes

Junior G

Junior G

0 likes

12/5 Trump just created a government enemies list??? -https://www.washingtonpost.com/politics/2025/11/28/trump-white-house-media-bias-tracker-hall-of-shame -https://www.reuters.com/world/us/trump-white-house-unveils-media-bias-webpage-amid-attacks-reporters-2025-11-28 -https://apnews.com/artic
Jaydin🦋

Jaydin🦋

1 like

#tiktok #fyp #foryou
user8575837197706

user8575837197706

2 likes

How to Make a Dyson Sphere in Sandboxels
#dysonsphere #science #sciencegames #gaming #pixelart
R74n

R74n

7 likes

Finding Relief * Panic Attack Addition
#growthmindset #lemon8challenge Following my last post, here are some tools you can use during your next panic attack. If you're anything like me you can't think when you are panicking. If these tools seem like they will work for you, tell the people your love and trust the too
Sha Dae Kennedy

Sha Dae Kennedy

218 likes

Ketogenic diet
Dr Jennah | WeightDoc

Dr Jennah | WeightDoc

3 likes

See more