RST TI Report Digest: 15 Dec 2025
ID: b1a058fc-06ca-54e0-9fff-5adf36f3b5a2
STIX ID: report--b1a058fc-06ca-54e0-9fff-5adf36f3b5a2
Feed Name: RST Cloud Blog
GrayBravo (aka TAG-150) operates a sophisticated malware-as-a-service ecosystem—deploying CastleLoader, CastleBot, CastleRAT and related tools—using phishing lures, malvertising, fake software updates and typosquatting to target multiple industries (notably logistics and hospitality). Recorded Future identifies four distinct activity clusters with unique tactics (e.g., ClickFix technique), extensive IOCs (IPs, domains, URLs, hashes, emails), and possible operational overlap with other actors such as Sparja.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
