GrayBravo (TAG-150) is a sophisticated threat actor known for custom CastleLoader and CastleRAT malware families.
Analyst brief
GrayBravo (TAG-150) is a sophisticated threat actor developing custom malware families such as CastleLoader and CastleRAT. The group targets various victim profiles primarily through phishing attacks that impersonate legitimate services. Key TTPs include the ClickFix technique, deceptive domains, fake repositories, and multi-layered infrastructure. Defenders should focus on monitoring suspicious domains, fake repositories, and unusual macro execution.
GrayBravo
TAG-150
unknown
TAG-150, also known as GrayBravo, is a sophisticated threat actor responsible for developing multiple custom malware families, including CastleLoader and CastleRAT, and operates a large-scale, multi-layered infrastructure. The group employs the ClickFix technique to distribute malware through phishing attacks that impersonate legitimate services, leveraging deceptive domains and fake repositories. Insikt Group has identified four distinct activity clusters associated with TAG-150, each targeting different victim profiles and utilizing unique TTPs.