GrayBravo, formerly tracked as TAG-150, is a financially motivated cybercriminal threat actor assessed to operate a malware-as-a-service ecosystem active since at least March 2025. The group is associated with rapid malware development, technical sophistication, responsiveness to public reporting, and a large, evolving, multi-tiered infrastructure. GrayBravo is best known as the operator and developer behind CastleLoader and related tooling including CastleRAT and CastleBot. Some reporting also links the actor’s ecosystem to CastleStealer distribution and to overlap with LummaStealer operations. GrayBravo commonly gains initial access through social engineering rather than software exploitation. Observed delivery methods include ClickFix-style lures that trick victims into manually executing malicious commands, phishing themed around logistics firms and Booking.com, fake browser or software update prompts, malvertising, and fraudulent code repositories impersonating legitimate software. The actor has shown particular effectiveness in campaigns that abuse procedural trust, including fake CAPTCHA and troubleshooting workflows, and has also used compromised or fraudulent business identities and code-signing artifacts to improve payload credibility. The actor’s malware ecosystem centers on CastleLoader, a modular loader used to deliver a wide range of secondary payloads. Reported follow-on malware includes CastleRAT, SectopRAT, WarmCookie, NetSupport RAT, HijackLoader, StealC, RedLine Stealer, Rhadamanthys, DeerStealer, MonsterV2, and LummaStealer. CastleRAT has been observed in both Python and C variants and supports system reconnaissance, command execution, payload download and execution, remote shell access, and in some variants keylogging and screen capture. GrayBravo has also been linked to newer Deno- and JavaScript-based tooling in campaigns involving DinDoor, DenoRAT, and NightshadeC2, reflecting continued experimentation with trusted runtimes and in-memory execution to reduce detection. GrayBravo’s tradecraft emphasizes layered infrastructure, redundancy, and evasion. Researchers have described Tier 1 victim-facing command-and-control servers backed by intermediary and higher-tier systems, with evidence of operational separation, fallback nodes, and occasional operational security lapses. The actor has used dead-drop resolvers, including Steam Community profiles, and has relied on obfuscation, reflective loading, DLL side-loading, in-memory execution, geofencing, anti-sandbox checks, and selective security-product awareness. Campaigns have also used loaders implemented in AutoIt, Python, JavaScript, and native code, indicating a flexible development model. Multiple activity clusters have been associated with the GrayBravo ecosystem. Reported sub-clusters include TAG-160, which has targeted the logistics sector using phishing and ClickFix techniques and has abused freight-matching platforms to enhance lure credibility, and TAG-161, which has used Booking.com-themed ClickFix campaigns and delivered both CastleLoader and Matanbuchus. Additional clusters have used malvertising, fake software updates, and brand impersonation to distribute CastleLoader and related payloads. Victimology spans logistics, financial services, government, critical infrastructure, IT, and other enterprise sectors, with campaigns observed against organizations in North America and elsewhere. GrayBravo is generally assessed as a Russian-speaking criminal actor or ecosystem, based on infrastructure patterns, malware behavior, and regional exclusions seen in associated campaigns. At the same time, some infrastructure and tooling linked to GrayBravo appears to have been used by other operators, including Iranian state-linked activity. Reporting has described MuddyWater as a likely customer or co-user of parts of the CastleRAT or CastleLoader ecosystem in operations against Israeli targets. This suggests GrayBravo’s tooling may be multi-tenant or service-based, complicating attribution when its malware is observed in intrusions. Known aliases include TAG-150. Known associated sub-groups or activity clusters include TAG-160 and TAG-161.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
77 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting financially targeted intrusions using ClickFix social engineering to trick users into executing malicious commands, leading to deployment of DinDoor, DenoRAT, and NightshadeC2 for persistence, credential theft, browser data theft, and host reconnaissance.
Abusing Deno in a multi-stage malware delivery chain beginning with a ClickFix-style social engineering lure and MSI installer, leading to DinDoor, DenoRAT, and in-memory execution of NightshadeC2 for RAT, stealer, remote control, and browser/crypto-wallet theft operations.
Threat activity cluster attributed with CastleLoader and associated distribution of CastleStealer in lure-based malware campaigns.
Uses shared backend infrastructure associated with the domain serialmenot[.]com for CastleLoader operations; DinDoor shows behavioral overlap with this activity cluster.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.