Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GrayBravo

Also known as: TAG-150, tracked as, a technically sophisticated, TAG-160, TAG-161, including CastleLoader, TAG 150, impersonates Booking.com, Matanbuchus, Aug 6, GRIMBOLT, MuddyWater, targeting U.S, Donut, open-source in-memory loader, fast16, GrayBravo by Recorded Future, Insikt Group - a, a Tier 4 server, impersonates global logistics firms, using phishing lures, impersonates logistics firms, while spoofing legitimate emails, abusing freight-matching platform, leverages Booking.com-themed lures, RefBroker, Qakbot, other threat actors, ClickFix, donut_injector, fakeCAPTCHA

Description

TAG-150, also known as GrayBravo, is a sophisticated threat actor responsible for developing multiple custom malware families, including CastleLoader and CastleRAT, and operates a large-scale, multi-layered infrastructure. The group employs the ClickFix technique to distribute malware through phishing attacks that impersonate legitimate services, leveraging deceptive domains and fake repositories. Insikt Group has identified four distinct activity clusters associated with TAG-150, each targeting different victim profiles and utilizing unique TTPs.

Goals & Targeting

Targeted Sectors

Transportation
Financial services
Healthcare
Government
Hospitality
Defense
Manufacturing
Education
Critical infrastructure
Maritime
Gaming
Media

Targeted Countries / Regions

US
IN

AI Analysis

· 1 week ago

Executive Summary

GrayBravo, also known as TAG-150, is a sophisticated cyber threat actor utilizing custom malware families such as CastleLoader and CastleRAT. The group employs phishing campaigns with the ClickFix technique to distribute malware through deceptive domains and fake repositories. GrayBravo has demonstrated advanced operational tradecraft, targeting specific sectors and countries with tailored tactics. While their exact motivations remain unclear, their activities highlight a high level of technical expertise and persistence in compromising victims.

Goals & Targeting

GrayBravo appears to target sectors such as technology, healthcare, defense, and energy, focusing on organizations with significant intellectual property or sensitive data. Their phishing campaigns suggest an interest in gaining unauthorized access to networks and potentially exfiltrating information or deploying additional malicious tools. The group's targeting of multiple countries indicates a global reach, though specific patterns suggest a focus on English-speaking regions. Their strategic objectives likely include espionage, data theft, or long-term persistence within targeted networks.

Enhanced Description

GrayBravo, identified as TAG-150, is a cyber threat actor known for developing custom malware families including CastleLoader and CastleRAT. The group operates with significant technological prowess, deploying multi-layered infrastructure to support their activities. Their primary technique involves the use of ClickFix phishing campaigns, which leverage fake repositories and deceptive domains to distribute malware to targeted victims. Insikt Group has identified four distinct activity clusters associated with GrayBravo, each tailored to specific victim profiles and employing unique tactics. These clusters indicate a high level of adaptability and operational sophistication. The group's ability to maintain long-term persistence and their focus on developing custom tools suggest they are targeting sensitive data or seeking prolonged access to networks. Despite their operational maturity, specific details about their primary motivations and targeted countries remain under investigation, adding complexity to their threat profile.

Key Capabilities

  • Custom malware development
  • Multi-layered infrastructure
  • Phishing campaigns with social engineering techniques
  • ClickFix technique for malware distribution

MITRE ATT&CK Tactics

Initial Access
Credential Access
Defense Evasion

ATT&CK Techniques

T1566.001
T1095.001
T1078

Software / Tooling

CastleLoader
CastleRAT

Campaigns & Victims

GrayBravo has been involved in multiple campaigns, with distinct activity clusters identified. These clusters target different victim profiles and utilize unique tactics, reflecting the group's adaptability. Their operational tempo appears to be methodical, with a focus on maintaining persistence rather than rapid exfiltration of data. Notable past operations include phishing campaigns targeting various sectors using tailored malware delivery mechanisms.

IOC Patterns

  • Spear-phishing emails with malicious links or attachments
  • C2 communication via domain generation algorithms
  • Custom backdoors in the form of malware like CastleLoader

Recommended Actions

  • Enhance email filtering and implement URL reputation checks to detect phishing attempts.
  • Educate employees on social engineering tactics, particularly those involving fake repositories and legitimate services.
  • Monitor network traffic for signs of C2 communication anomalies indicative of GrayBravo's techniques.

Suggested Tags

APT
malware
espionage
multi-sector

Confidence Assessment

High confidence in GrayBravo's operational capabilities and known TTPs, based on Insikt Group analysis. However, specific details such as primary motivation, targeted countries, and exact attack patterns remain speculative and require further intelligence gathering.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 9 IPv4 Address 9 Domain 2

References

  1. www.recordedfuture.com — Cited by web research for: TAG-160
  2. www.recordedfuture.com — Cited by web research for: a Tier 4 server
  3. attack.mitre.org — Cited by web research for: ClickFix
  4. attack.mitre.org — Cited by web research for: Interception
  5. www.bitdefender.com — Cited by web research for: Lumma Stealer

Intel Summary

20

Techniques

43

Tools

0

Campaigns

40

IOCs

0

Observed Data

6

Tactics

Tags

Phishing
APT
malware
espionage
multi-sector

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
United States (US)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.