Threat Intelligence

Activity of CastleLoader expands amid improvements

Red Skull Icon Formed From Binary Code on Computer Screen

Malware loader CastleLoader, which was developed by GrayBravo or TAG-150, has been tapped by four different threat activity clusters since March, according to The Hacker News.

Organizations in the logistics sector were compromised with CastleLoader via phishing and ClickFix tactics by the TAG-160 threat cluster since March, a report from Recorded Future's Insikt Group revealed. ClickFix techniques exploiting Booking.com have been used by TAG-161 to spread the loader alongside Matanbuchus 3.0 since June.

Similar tactics were harnessed by the third cluster, which used CastleLoader to deliver CastleRAT since March, while malvertising and bogus software updates were used by the final cluster to distribute CastleLoader and NetSupport RAT since April. Additional findings showed GrayBravo to have implemented a multi-tiered infrastructure, including victim-facing command-and-control servers and various VPS servers.

Such expanded use of CastleLoader "highlights how technically advanced and adaptive tooling, particularly from a threat actor with GrayBravo's reputation, can rapidly proliferate within the cybercriminal ecosystem once proven effective," said researchers.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds