logo

From CastleLoader to CastleRAT: TAG-150 Advances Operations with Multi-Tiered Infrastructure

ID: e7ca0a81-1239-5a81-9c54-fe5e18903d9b

STIX ID: report--e7ca0a81-1239-5a81-9c54-fe5e18903d9b

Feed Name: Recorded Future Blog

Threat Score
75/100

Date Published: 2025-09-04

Date Updated: 2026-04-28

...
...

Insikt Group identifies TAG-150, an active cybercriminal actor since March 2025 that operates a large multi-tier infrastructure and deploys multiple malware families (CastleLoader, CastleBot, and the newly documented CastleRAT in Python and C variants) to deliver RATs, information stealers, and secondary payloads; the report details C2 infrastructure, services used (file sharing, anti-detection, Oxen/Tox), victimology, IoCs, detection rules, and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.