All threat actors

GrayBravo

Alert me

A cybercriminal malware-development and distribution cluster, formerly tracked as TAG-150, associated with CastleLoader, CastleBot, and CastleRAT. Active since 2025, it appears to provide loader or malware-as-a-service capabilities to multiple campaigns and access chains.

Also known as

TAG-150

Create a free account to see the reports

Sign in or create a free account to see every report that names GrayBravo.

Create free account