Four Threat Clusters Using CastleLoader as GrayBravo Expands Its Malware Service Infrastructure
A malware loader called CastleLoader has been used by four different threat activity clusters, supporting the earlier conclusion that the tool is made available to other threat actors via a malware-as-a-service (MaaS) paradigm.
Recorded Future's Insikt Group, which was previously tracking the threat actor responsible for CastleLoader as TAG-150, has given it the name GrayBravo.
According to an analysis released today, GrayBravo, which is owned by Mastercard, is distinguished by quick development cycles, technical competence, responsiveness to public reporting, and a vast, dynamic infrastructure.
A remote access trojan known as CastleRAT and a malware framework known as CastleBot, which consists of a shellcode stager/downloader read more about Four Threat Clusters Using CastleLoad...

