From CastleLoader to CastleRAT: TAG-150 Advances Operations with Multi-Tiered Infrastructure
ID: e7ca0a81-1239-5a81-9c54-fe5e18903d9b
STIX ID: report--e7ca0a81-1239-5a81-9c54-fe5e18903d9b
Feed Name: Recorded Future Blog
Threat Score
Insikt Group identifies TAG-150, an active cybercriminal actor since March 2025 that operates a large multi-tier infrastructure and deploys multiple malware families (CastleLoader, CastleBot, and the newly documented CastleRAT in Python and C variants) to deliver RATs, information stealers, and secondary payloads; the report details C2 infrastructure, services used (file sharing, anti-detection, Oxen/Tox), victimology, IoCs, detection rules, and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
