CastleStealer Malware Bypasses Chromium ABE and Adds Remote Command Execution Capabilities
What happened
CastleStealer, a C# information stealer first publicly identified in April 2026, has expanded its capabilities beyond credential theft. New samples analyzed by Flashpoint bypass Chromium app-bound encryption (scrambling data so only the holder of the key can read it), support remote command execution, and transmit stolen data through small, encrypted TCP exchanges instead of uploading a single archive.
Flashpoint has not observed widespread adoption among threat actors (the person or group behind an attack). [โฆ] The post CastleStealer Malware Bypasses Chromium ABE and Adds Remote Command Execution Capabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform .
Sources & evidence
- GBHackers Reporting source
CastleStealer Malware Bypasses Chromium ABE and Adds Remote Command Execution Capabilities โ
https://gbhackers.com/castlestealer-malware/