All threat actors

TAG161

Alert me

A financially motivated phishing and malware-delivery cluster active since 2025. It uses Booking.com-themed lures and ClickFix-style instructions to deliver loaders such as CastleLoader or Matanbuchus and establish access for follow-on cybercrime.

Create a free account to see the reports

Sign in or create a free account to see every report that names TAG161.

Create free account