Most Significant TTP 2026: CastleLoader Multi-Stage Downloader Execution Pattern
Detects execution of rundll32.exe or regsvr32.exe when spawned by powershell.exe or mshta.exe, specifically targeting DLLs located in common user-writable or temporary directories (AppData, ProgramData, Downloads). This pattern is consistent with the delivery of CastleLoader shellcode loaders following ClickFix-style social engineering lures.
Sigma

