GrayBravo, formerly tracked as TAG-150, is a financially motivated cybercriminal threat actor assessed to operate a malware-as-a-service ecosystem centered on the CastleLoader malware family. Active since at least March 2025, the group is notable for rapid development cycles, technical sophistication, responsiveness to public reporting, and a large, evolving multi-tier infrastructure. GrayBravo is associated with the development and operation of CastleLoader, CastleRAT, CastleBot, and related tooling, and its ecosystem has also been linked to CastleStealer and other payload delivery activity. GrayBravo commonly gains initial access through social engineering rather than software exploitation. Observed delivery methods include ClickFix-style lures that trick victims into manually executing malicious commands, fake CAPTCHA and troubleshooting pages, malvertising, fraudulent software installers and updates, and bogus or compromised code repositories impersonating legitimate software and business services. The actor has also used sector-themed phishing and impersonation, including logistics and travel-related branding, to increase credibility and improve victim conversion. The group’s tooling is modular and supports multi-stage intrusion chains. CastleLoader functions as a loader used to deploy a wide range of secondary malware, including information stealers, remote access trojans, and additional loaders. Reported downstream payloads associated with GrayBravo operations include LummaStealer, StealC, RedLine Stealer, Rhadamanthys, DeerStealer, NetSupport RAT, WarmCookie, SectopRAT, HijackLoader, MonsterV2, and other commodity malware. CastleRAT, observed in both Python and C variants, provides remote command execution, payload download and execution, system reconnaissance, and in some variants credential theft, keylogging, and screen capture. Related activity has also shown use of Deno- and Python-based loaders and RATs in complex staged infections. GrayBravo’s infrastructure is characterized by layered operational design and redundancy. Reporting has described victim-facing command-and-control nodes backed by intermediary and higher-tier systems, overlapping infrastructure, shared cryptographic material across servers, dead-drop resolver techniques using public web services, and frequent use of typosquatted, re-registered, or impersonating domains. The actor has demonstrated adaptability in rotating delivery mechanisms, hosting, and malware variants, and some infrastructure has overlapped with operations involving LummaStealer. Multiple distinct activity clusters have been identified within the broader GrayBravo ecosystem, including TAG-160 and TAG-161, which have used different lures, sectors, and payload combinations while relying on CastleLoader as a common delivery platform. GrayBravo is widely assessed as a criminal actor rather than a nation-state group, with indications consistent with Russian-speaking operators in some reporting. At the same time, parts of its infrastructure and malware ecosystem appear to be multi-tenant or service-oriented, and there is reporting that other actors, including Iranian state-linked operators such as MuddyWater, may have used GrayBravo-associated tooling or backend services in some operations. That overlap complicates attribution of individual intrusions, but does not change the core assessment that GrayBravo itself is a cybercriminal operator and malware service provider.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
77 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Abusing Deno in a multi-stage malware delivery chain beginning with a ClickFix-style social engineering lure and MSI installer, leading to DinDoor, DenoRAT, and in-memory execution of NightshadeC2 for RAT, stealer, remote control, and browser/crypto-wallet theft operations.
Threat activity cluster attributed with CastleLoader and associated distribution of CastleStealer in lure-based malware campaigns.
Uses shared backend infrastructure associated with the domain serialmenot[.]com for CastleLoader operations; DinDoor shows behavioral overlap with this activity cluster.
Attributed with using serialmenot[.]com as backend infrastructure for CastleLoader and discussed as a likely operator pattern in a financially themed targeting context.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.