TI Mindmap HUB
Threat Intelligence Report

Behind the Walls: Techniques and Tactics in Castle RAT Client Malware | Splunk

๐Ÿ“… December 6, 2025 ๐Ÿ“ฐ www.splunk.com ๐Ÿ” 1 CVE(s) referenced

CastleRAT is a sophisticated remote access trojan actively deployed in 2025, featuring stealthy C and Python variants that enable attackers to exfiltrate sensitive data, hijack user sessions, escalate privileges, and maintain persistent control over compromised Windows systems through advanced techniques like clipboard scraping, keylogging, browser hijacking, and UAC bypass.

vendor
CVE-2020-0601

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

๐Ÿ” Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

๐Ÿ“Š Visual Mindmap
๐ŸŽฏ IOC Extraction
โš”๏ธ MITRE ATT&CK TTPs
๐Ÿ“ฆ STIX 2.1 Bundle