Malware loader CastleLoader, which was developed by GrayBravo or TAG-150, has been tapped by four different threat activity clusters since March, according to The Hacker News.Organizations in the logistics sector were compromised with CastleLoader via phishing and ClickFix tactics by the TAG-160 threat cluster since March, a report from Recorded Future's Insikt Group revealed. ClickFix techniques exploiting Booking.com have been used by TAG-161 to spread the loader alongside Matanbuchus 3.0 since June.Similar tactics were harnessed by the third cluster, which used CastleLoader to deliver CastleRAT since March, while malvertising and bogus software updates were used by the final cluster to distribute CastleLoader and NetSupport RAT since April. Additional findings showed GrayBravo to have implemented a multi-tiered infrastructure, including victim-facing command-and-control servers and various VPS servers.Such expanded use of CastleLoader "highlights how technically advanced and adaptive tooling, particularly from a threat actor with GrayBravo's reputation, can rapidly proliferate within the cybercriminal ecosystem once proven effective," said researchers.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
