GrayBravo, formerly tracked as TAG-150, is a Russian-speaking cybercriminal threat actor assessed to operate a malware-as-a-service ecosystem centered on CastleLoader and CastleRAT. Active since at least March 2025, the group is characterized by rapid malware development, technical sophistication, and a large, evolving multi-tier infrastructure. GrayBravo has been linked to CastleLoader, CastleBot, CastleRAT, CastleStealer, DinDoor-related activity overlaps, and NightshadeC2-associated intrusion chains, and its tooling has been used to deliver a wide range of secondary payloads including commodity stealers, remote access trojans, and other loaders. GrayBravo commonly gains initial access through ClickFix-style social engineering and fraudulent software distribution, including fake GitHub repositories and malicious ads or installer lures. Victims are often tricked into executing PowerShell or Run-dialog commands that fetch MSI, NSIS, AutoIt, Python, or Deno-based stages. Observed infection chains include installation or abuse of legitimate runtimes such as Deno and Python, followed by staged retrieval of DinDoor, DenoRAT, CastleLoader, CastleRAT, or NightshadeC2 components. The actor has also used DLL side-loading, in-memory execution, steganographic payload concealment, dead-drop resolvers, and geofencing or CIS-exclusion logic consistent with Russian-speaking financially motivated operators. Its malware supports reconnaissance, persistence, command execution, payload delivery, browser and wallet data theft, screenshot capture, keylogging, remote shell access, and broader post-compromise activity. CastleRAT variants have been documented in both Python and C, with capabilities including system data collection, download-and-execute functionality, remote command execution, and in the C variant, keylogging and screen capture. DenoRAT- and NightshadeC2-linked chains attributed to GrayBravo additionally demonstrate browser credential and cookie theft, cryptocurrency wallet targeting, optional Chromium protection bypass through DLL injection, and reflective in-memory loading. GrayBravo infrastructure has been observed in a tiered architecture with victim-facing command-and-control servers, intermediary VPS layers, and higher-tier operational systems. Reporting has also associated the actor with use of Tox and the Oxen network, as well as operational overlap with services and infrastructure used to support malware delivery and administration. Multiple activity clusters have been observed leveraging the ecosystem, supporting the assessment that GrayBravo operates a MaaS platform rather than a single narrow campaign. The actor is primarily financially motivated. GrayBravo tooling has been associated with delivery of stealers and loaders used in credential theft and monetization-focused intrusions, including campaigns affecting financial institutions, government entities, critical infrastructure, IT firms, and logistics organizations. Separate reporting also indicates that the Iranian state-linked espionage actor MuddyWater has operated as a customer of the GrayBravo CastleRAT ecosystem against Israeli targets, underscoring that GrayBravo's criminal platform can be consumed by other threat actors, including state operators. Known aliases include TAG-150 and GrayBravo.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
45 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
Israeli-Focused Targeting Set Targets include Israeli IP ranges, Laravel web applications, and FortiOS systems. ... MITRE ATT&CK ID Technique ... T1190 CVE-2024-55591, CVE-2024-23113, CVE-2026-1281
Israeli-Focused Targeting Set Targets include Israeli IP ranges, Laravel web applications, and FortiOS systems. ... MITRE ATT&CK ID Technique ... T1190 CVE-2024-55591, CVE-2024-23113, CVE-2026-1281
Israeli-Focused Targeting Set Targets include Israeli IP ranges, Laravel web applications, and FortiOS systems. ... MITRE ATT&CK ID Technique ... T1190 CVE-2024-55591, CVE-2024-23113, CVE-2026-1281
93 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting financially targeted intrusions using ClickFix social engineering to trick users into executing malicious commands, leading to deployment of DinDoor, DenoRAT, and NightshadeC2 for persistence, credential theft, browser data theft, and host reconnaissance.
Abusing Deno in a multi-stage malware delivery chain beginning with a ClickFix-style social engineering lure and MSI installer, leading to DinDoor, DenoRAT, and in-memory execution of NightshadeC2 for RAT, stealer, remote control, and browser/crypto-wallet theft operations.
Threat activity cluster attributed with CastleLoader and associated distribution of CastleStealer in lure-based malware campaigns.
A Russian-speaking criminal ecosystem/developer associated with the CastleRAT malware-as-a-service platform that is operationally linked to MuddyWater in this reporting.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.