GrayBravo, a technically advanced threat actor previously tracked as TAG-150, has expanded its operations by leveraging the CastleLoader malware in a malware-as-a-service (MaaS) model. Recent analysis identified four distinct activity clusters, each employing unique tactics and targeting different industries, including logistics and hospitality. These clusters utilize sophisticated phishing techniques, such as impersonating global logistics firms and Booking.com, and employ the ClickFix method to distribute CastleLoader alongside other malware like Matanbuchus and CastleRAT. The infrastructure supporting these campaigns is large-scale and multi-layered, demonstrating GrayBravo's adaptability and rapid development cycles.
The CastleLoader framework enables the delivery of various payloads, including infostealers (DeerStealer, RedLine Stealer, StealC Stealer), remote access trojans (NetSupport RAT, SectopRAT, MonsterV2, WARMCOOKIE), and additional loaders. Security researchers have linked the online persona "Sparja" to GrayBravo's activities, further highlighting the group's presence on underground forums. Defenders are advised to block associated IPs and domains, monitor for unusual connections to legitimate internet services, and deploy updated detection rules. Comprehensive lists of indicators of compromise (IoCs) and mitigation strategies have been provided to help organizations defend against these evolving threats.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Blackpoint Cyber reported a new evolution of CastleLoader in which victims are socially engineered via ClickFix to run commands that launch an in-memory Python-based loader using pythonw.exe. The updated delivery chain was described as improving stealth by avoiding disk writes and using evasion techniques such as PEB walking and in-memory shellcode execution.
Recorded Future disclosed that GrayBravo's operations can be divided into four distinct activity clusters with different tactics, victim profiles, and delivery methods, including phishing, malvertising, fake software updates, and impersonation of logistics firms and Booking.com. The analysis also highlighted overlapping and redundant infrastructure supporting these campaigns.
Recorded Future and other reporting describe GrayBravo, formerly tracked as TAG-150, as operating CastleLoader and related tools such as CastleRAT and CastleBot through a large, multi-layered malware-as-a-service infrastructure. The reporting does not specify when the operation began, only that it was active by the time of publication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcerecordedfuture.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.