CastleRAT attack first to abuse Deno JavaScript runtime to evade enterprise security
Reported 11 Mar 2026 by otx · Severity: medium
A sophisticated infection chain has been discovered that installs CastleRAT malware without leaving traces on disk. The attack uniquely abuses the Deno runtime as a malicious framework, combining social engineering, steganography, and in-memory execution to evade detection. The p