Also known as: TAG-150, tracked as, a technically sophisticated, TAG-160, TAG-161, including CastleLoader, TAG 150, impersonates Booking.com, Matanbuchus, Aug 6, GRIMBOLT, MuddyWater, targeting U.S, Donut, open-source in-memory loader, fast16, GrayBravo by Recorded Future, Insikt Group - a, a Tier 4 server, impersonates global logistics firms, using phishing lures, impersonates logistics firms, while spoofing legitimate emails, abusing freight-matching platform, leverages Booking.com-themed lures, RefBroker, Qakbot, other threat actors, ClickFix, donut_injector, fakeCAPTCHA
TAG-150, also known as GrayBravo, is a sophisticated threat actor responsible for developing multiple custom malware families, including CastleLoader and CastleRAT, and operates a large-scale, multi-layered infrastructure. The group employs the ClickFix technique to distribute malware through phishing attacks that impersonate legitimate services, leveraging deceptive domains and fake repositories. Insikt Group has identified four distinct activity clusters associated with TAG-150, each targeting different victim profiles and utilizing unique TTPs.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
GrayBravo, also known as TAG-150, is a sophisticated cyber threat actor utilizing custom malware families such as CastleLoader and CastleRAT. The group employs phishing campaigns with the ClickFix technique to distribute malware through deceptive domains and fake repositories. GrayBravo has demonstrated advanced operational tradecraft, targeting specific sectors and countries with tailored tactics. While their exact motivations remain unclear, their activities highlight a high level of technical expertise and persistence in compromising victims.
Goals & Targeting
GrayBravo appears to target sectors such as technology, healthcare, defense, and energy, focusing on organizations with significant intellectual property or sensitive data. Their phishing campaigns suggest an interest in gaining unauthorized access to networks and potentially exfiltrating information or deploying additional malicious tools. The group's targeting of multiple countries indicates a global reach, though specific patterns suggest a focus on English-speaking regions. Their strategic objectives likely include espionage, data theft, or long-term persistence within targeted networks.
Enhanced Description
GrayBravo, identified as TAG-150, is a cyber threat actor known for developing custom malware families including CastleLoader and CastleRAT. The group operates with significant technological prowess, deploying multi-layered infrastructure to support their activities. Their primary technique involves the use of ClickFix phishing campaigns, which leverage fake repositories and deceptive domains to distribute malware to targeted victims. Insikt Group has identified four distinct activity clusters associated with GrayBravo, each tailored to specific victim profiles and employing unique tactics. These clusters indicate a high level of adaptability and operational sophistication. The group's ability to maintain long-term persistence and their focus on developing custom tools suggest they are targeting sensitive data or seeking prolonged access to networks. Despite their operational maturity, specific details about their primary motivations and targeted countries remain under investigation, adding complexity to their threat profile.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GrayBravo has been involved in multiple campaigns, with distinct activity clusters identified. These clusters target different victim profiles and utilize unique tactics, reflecting the group's adaptability. Their operational tempo appears to be methodical, with a focus on maintaining persistence rather than rapid exfiltration of data. Notable past operations include phishing campaigns targeting various sectors using tailored malware delivery mechanisms.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in GrayBravo's operational capabilities and known TTPs, based on Insikt Group analysis. However, specific details such as primary motivation, targeted countries, and exact attack patterns remain speculative and require further intelligence gathering.
No campaigns linked yet.
No observed data linked yet.
20
Techniques
43
Tools
0
Campaigns
40
IOCs
0
Observed Data
6
Tactics