logo

GrayBravo’s CastleLoader Activity Clusters Target Multiple Industries

ID: fce5f4a1-fb0f-5ec2-b340-9bb14b9e7b57

STIX ID: report--fce5f4a1-fb0f-5ec2-b340-9bb14b9e7b57

Feed Name: Recorded Future Blog

Threat Score
78/100

Date Published: 2025-12-09

Date Updated: 2026-07-19

...
...

Insikt Group tracks GrayBravo (formerly TAG-150), a technically sophisticated malware-as-a-service operator responsible for CastleLoader, CastleRAT and related tooling; the report identifies four distinct activity clusters (including TAG-160 targeting logistics and TAG-161 impersonating Booking.com), details multi-tiered RC4-encrypted C2 infrastructure, numerous IoCs (domains, IPs, Steam deaddrops, Snort/YARA/Sigma rules), and provides mitigations to detect and block infections and associated infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.