All threat actorsAlert me
GrayBravo
A cybercriminal malware-development and distribution cluster, formerly tracked as TAG-150, associated with CastleLoader, CastleBot, and CastleRAT. Active since 2025, it appears to provide loader or malware-as-a-service capabilities to multiple campaigns and access chains.
Also known as
TAG-150
Create a free account to see the reports
Sign in or create a free account to see every report that names GrayBravo.
Create free account