TAG-150 Hackers Escalate Attacks with Proprietary Malware Families
A sophisticated threat actor, identified as TAG-150, has been active since at least March 2025. This group is known for rapid malware development, technical sophistication, and a complex multi-tiered infrastructure. TAG-150 has developed several malware…
A sophisticated threat actor, identified as TAG-150, has been active since at least March 2025. This group is known for rapid malware development, technical sophistication, and a complex multi-tiered infrastructure. TAG-150 has developed several malware families, including CastleLoader, CastleBot, and CastleRAT, which are used in phishing campaigns and fraudulent repositories targeting organizations.
Initially, TAG-150 introduced CastleLoader, a loader that delivers various payloads such as information stealers and remote access trojans. Following this, CastleBot, another loader variant, was released. In early August 2025, Insikt Group reported on CastleRAT, a remote access trojan available in both Python and C variants, capable of system reconnaissance, payload download and execution, and remote shell commands.
The C variant of CastleRAT includes advanced functions like keylogging, screen capture, file upload/download, and process termination, indicating ongoing feature expansions.
Research by Recorded Future’s Insikt Group reveals that TAG-150’s infrastructure operates on a four-tier model:
Tier 1: Victim-facing command-and-control (C2) servers for malware families such as CastleLoader, CastleRAT, SectopRAT, and WarmCookie. Tier 2: VPS intermediaries accessed over RDP, used to stage connections to Tier 1. Tier 3: Includes two clusters: a set of VPS servers with shared TLS certificates and a Russian residential IP using Tox, suggesting possible affiliate or secondary operator involvement. Tier 4: Serves as a backup layer, with long-running high-port UDP sessions connecting VPS nodes.
These servers are registered through NameCheap or TUCOWS and hosted across multiple autonomous systems, with providers like servinga GmbH and FEMO IT Solutions.
A sophisticated threat actor, identified as TAG-150, has been active since at least March 2025.
TAG-150 primarily uses phishing attacks themed around Cloudflare and fake GitHub repositories to trick victims into executing PowerShell commands. Despite modest overall click-through rates, approximately 29% of engaged users became infected, highlighting the campaign's effectiveness.
Recorded Future intelligence indicates that targets are primarily located in the United States, including private individuals and potentially enterprise networks, though few organizations have publicly reported breaches.
TAG-150 employs various cybercriminal tools and platforms, including Kleenscan for anti-detection, the Oxen network for secure communications, file-sharing services like temp.sh and mega.nz, the cryptocurrency swap site simpleswap.io, and underground forums like Exploit Forum. The data scope has expanded to include city, ZIP code, and indicators of VPN, proxy, or Tor node usage.
These services facilitate hosting payloads, anonymizing traffic, and managing C2 infrastructure.
Security teams are advised to implement the following measures:
Block IP addresses and domains associated with CastleLoader, CastleBot, CastleRAT, and other related malware. Monitor and potentially block unusual file-sharing or paste services such as Pastebin. Deploy YARA, Snort, and Sigma rules for malware signature detection. Implement robust email filtering to intercept phishing attempts. Monitor for abnormal data exfiltration using network-intelligence platforms.
Appendix A of the Insikt Group report provides a comprehensive list of Indicators of Compromise (IoCs), while Appendices C–E offer detection rules for SIEM and endpoint platforms.
TAG-150 is expected to continue enhancing its toolkit and stealth capabilities. Security practitioners should remain vigilant, monitor TAG-150’s evolving infrastructure, and adopt proactive defenses to mitigate the threat posed by this emerging actor. Insikt Group will continue tracking TAG-150’s activities, reporting new developments, and updating detection strategies accordingly.
Based on reporting by GBHackers.
