GrayBravo, a technically advanced threat actor previously tracked as TAG-150, has expanded its operations by leveraging the CastleLoader malware in a malware-as-a-service (MaaS) model. Recent analysis identified four distinct activity clusters, each employing unique tactics and targeting different industries, including logistics and hospitality. These clusters utilize sophisticated phishing techniques, such as impersonating global logistics firms and Booking.com, and employ the ClickFix method to distribute CastleLoader alongside other malware like Matanbuchus and CastleRAT. The infrastructure supporting these campaigns is large-scale and multi-layered, demonstrating GrayBravo's adaptability and rapid development cycles.
The CastleLoader framework enables the delivery of various payloads, including infostealers (DeerStealer, RedLine Stealer, StealC Stealer), remote access trojans (NetSupport RAT, SectopRAT, MonsterV2, WARMCOOKIE), and additional loaders. Security researchers have linked the online persona "Sparja" to GrayBravo's activities, further highlighting the group's presence on underground forums. Defenders are advised to block associated IPs and domains, monitor for unusual connections to legitimate internet services, and deploy updated detection rules. Comprehensive lists of indicators of compromise (IoCs) and mitigation strategies have been provided to help organizations defend against these evolving threats.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Blackpoint Cyber reported a new evolution of CastleLoader in which victims are socially engineered via ClickFix to run commands that launch an in-memory Python-based loader using pythonw.exe. The updated delivery chain was described as improving stealth by avoiding disk writes and using evasion techniques such as PEB walking and in-memory shellcode execution.
Recorded Future disclosed that GrayBravo's operations can be divided into four distinct activity clusters with different tactics, victim profiles, and delivery methods, including phishing, malvertising, fake software updates, and impersonation of logistics firms and Booking.com. The analysis also highlighted overlapping and redundant infrastructure supporting these campaigns.
Recorded Future and other reporting describe GrayBravo, formerly tracked as TAG-150, as operating CastleLoader and related tools such as CastleRAT and CastleBot through a large, multi-layered malware-as-a-service infrastructure. The reporting does not specify when the operation began, only that it was active by the time of publication.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcerecordedfuture.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.