BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

GrayBravo’s CastleLoader Malware Expands Across Four Threat Clusters

GrayBravo's CastleLoader: Four Malware Clusters Target Logistics, Booking.com Scams, and Malvertising with Evolving Infrastructure

  • Four separate threat clusters use the CastleLoader Malware under a malware-as-a-service model.
  • The threat group behind CastleLoader is identified as GrayBravo, known for technical sophistication and a rapidly evolving infrastructure.
  • CastleLoader’s framework distributes various malware families including DeerStealer, RedLine Stealer, and NetSupport RAT.
  • Distinct clusters target logistics, Booking.com-themed scams, and use malvertising campaigns.
  • GrayBravo employs layered infrastructure and compromised accounts to enhance phishing campaign credibility.

In recent Cybersecurity developments, four distinct threat clusters have been observed deploying the CastleLoader malware loader. The actor responsible, designated as GrayBravo, operates under a malware-as-a-service (MaaS) model and is noted for its rapid development and complex infrastructure. These activities have been ongoing since at least March 2025.

- Advertisement -

GrayBravo, previously tracked as TAG-150, uses an advanced toolset including a remote access trojan named CastleRAT and a malware framework called CastleBot. This framework has components such as a shellcode stager, loader, and core backdoor, enabling communication with command-and-control (C2) servers to execute payloads like DLL, EXE, and PE files. CastleLoader distributes malware families such as DeerStealer, RedLine Stealer, StealC Stealer, NetSupport RAT, SectopRAT, MonsterV2, WARMCOOKIE, and other loaders like Hijack Loader.

The four activity clusters identified each employ different tactics. Cluster 1 (TAG-160) targets the logistics sector using phishing and ClickFix (a browser auto-click technique) since March 2025. Cluster 2 (TAG-161) uses Booking.com-themed ClickFix campaigns to spread CastleLoader and Matanbuchus 3.0, active since June 2025. Cluster 3 impersonates Booking.com infrastructure, combining ClickFix and Steam Community dead drop resolvers to deliver CastleRAT through CastleLoader, also active since March 2025. Lastly, Cluster 4 leverages malvertising and fake software updates posing as Zabbix and RVTools to distribute CastleLoader and NetSupport RAT, active since April 2025.

The operation involves a multi-tier infrastructure including victim-facing Tier 1 C2 servers linked to malware families like CastleLoader and CastleRAT, supported by multiple backup VPS servers. Notably, Cluster 1 uses compromised or fraudulent accounts on freight-matching platforms such as DAT Freight & Analytics and Loadlink Technologies to lend credibility to phishing campaigns, demonstrating industry-specific knowledge.

“GrayBravo has significantly expanded its user base, evidenced by the growing number of threat actors and operational clusters leveraging its CastleLoader malware,” the analysis noted, highlighting the rapid adoption of these advanced tools within the cybercrime ecosystem. Further information about GrayBravo’s CastleLoader activity clusters is available in the detailed Recorded Future report.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

NY Atty Seeks to Unmask ‘Noah Doe’ Claiming $245B in BTC

An anonymous entity seeks legal title to ~3.8 million dormant BTC, including Satoshi's, valued...

Andrew Cuomo to co-chair ICE-OKX digital assets venture

OKX and Intercontinental Exchange (ICE), parent of the NYSE, announced a joint venture co-chaired...

Critical Flaws in Dify AI Platform Expose User Data

Critical vulnerabilities in the popular open-source AI platform Dify could have allowed attackers to...

SpaceX Stock Path to $300 Hinges on Starship, AI Gains

SpaceX stock, trading near $185, faces one of Wall Street's widest price target ranges,...

Taiko Bridge Attack: $1.7M Stolen, Users Told to Withdraw

The developers behind the Taiko Ethereum layer-2 network confirmed its chain state verification mechanism...

Must Read

Top 9 VPNs That Accept Bitcoin And Crypto

CyberGhost | FastVPN | TorGuard | Private Internet Access | ExpressVPN | NordVPN | Private VPN | SurfShark | AirVPN | Why Buy VPN...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading