Executive Summary
Facts Only
* ClearFake ranked first in the threat list.
* KongTuke ranked second.
* CastleLoader ranked fifth.
* Atomic Stealer ranked sixth.
* ACR Stealer ranked seventh.
* MacSync Stealer ranked seventh.
* NetSupport Manager ranked seventh.
* ClearFake uses JavaScript injection and fake CAPTCHA lures for malware delivery via drive-by download.
* KongTuke uses compromised WordPress sites to deploy malicious code.
* CastleLoader can deliver payloads including NetSupport Manager, CastleRAT, and an unnamed .NET-based information stealer.
* CastleLoader campaigns used paste and run techniques.
* Initial execution often involved caret-obfuscated commands using finger.exe.
* The process injection involved fetching and executing a Python script that extracted a CastleLoader binary.
Full Take
The narrative demonstrates an evolution in adversary techniques focusing heavily on deception during initial user interaction. ClearFake establishes the prevalence of social engineering through fake security checkpoints, indicating that bypassing perceived security measures remains a primary vector for malware deployment. The involvement of KongTuke highlights the persistence of exploiting legitimate web infrastructure (WordPress) as a staging ground for wider distribution, suggesting an ongoing reliance on established, trusted platforms to obfuscate malicious activity. CastleLoader’s detailed execution chain—involving sophisticated command obfuscation via caret use and self-contained Bring-Your-Own-Interpreter Python scripts—reveals an advanced operational focus on evading endpoint detection by leveraging legitimate system tools in novel ways for payload delivery. The detection opportunity identified regarding the use of caret obfuscation points toward a need to monitor command-line processing behavior not just for obvious strings, but for structural anomalies within execution commands themselves. The pattern suggests an adversarial preference for layered evasion, moving from initial lure (ClearFake) to distribution infrastructure (KongTuke) to sophisticated payload delivery (CastleLoader), with the focus shifting to obfuscating the mechanism of execution itself.
Bridge Questions: How do defensive measures need to adapt when adversaries consistently utilize legitimate system calls and interpreter tricks for execution? What systemic changes are required to mitigate the risk posed by exploiting seemingly legitimate web platforms like WordPress for malicious deployment? What is the long-term viability of relying on signature or behavior detection when payload delivery relies on dynamically constructed, multi-layered scripting obfuscation?
From the original · Red Canary
Zscaler Blog Get the latest Zscaler blog updates in your inbox Intelligence Insights: July 2026 ClearFake claims the crown again and CastleLoader debuts in this month’s edition of Intelligence Insights. This article was originally published by Red Canary, which is now part of Zscaler.Read the full story at redcanary.com
Sentinel — Human
The text reads like authentic threat intelligence reported by a security research entity, characterized by deep technical detail rather than broad, synthesized commentary.
