CastleBot is a Windows malware-as-a-service framework associated with the GrayBravo threat actor, formerly tracked as TAG-150. It comprises a shellcode stager/downloader, a loader, and a core backdoor module. The loader injects the core module, which communicates with command-and-control infrastructure to obtain tasks and download and execute additional DLL, executable, and PE payloads. CastleBot has been used to distribute secondary malware, including WARMCOOKIE, information stealers, and Rhadamanthys.
CastleBot has been propagated through ClickFix social-engineering attacks and fraudulent repositories impersonating legitimate software projects. In ClickFix activity, victims are persuaded to execute attacker-provided commands themselves. The framework has also been observed modifying the Windows hotpatch-management routine in memory to bypass Windows 11 and Windows Server mitigations that interfere with classic RunPE and Early Bird process-injection techniques.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Since emerging in March 2025, TAG-150 has deployed multiple likely self-developed malware families, starting with CastleLoader and CastleBot, and most recently CastleRAT...
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Bumblebee’s injection module ( dij command for DLL Injection) dynamically resolves NtQueueApcThread at runtime and uses it to inject a payload DLL... While the static import of NtQueueApcThread is flagged by multiple scanners, a runtime GetProcAddress lookup on ntdll.dll is invisible to import-table analysis.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that patches NtManageHotPatch in memory to bypass Windows mitigation and restore Early Bird APC and RunPE execution reliability.
Bot malware developed by the GrayBravo threat actor, likely used for automated malicious activities.
CastleBot is a custom malware family developed by GrayBravo, likely functioning as a botnet component within their ecosystem.
CastleBot is a modular malware framework consisting of a stager/downloader, loader, and a core backdoor, used to inject modules and retrieve tasks from C2 servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.