Sunday, 7 September

Saturday, 6 September2025

TAG-150 Hackers Deploy Self-Developed Malware Families to Attack Organizations

TAG-150 Hackers Deploy Self-Developed Malware Families to Attack Organizations
TAG-150, a sophisticated threat actor active since March 2025, has developed and deployed multiple self-created malware families, including CastleLoader, CastleBot, and the recently identified CastleRATa remote access trojan. These attacks primarily utilize Cloudflare-themed phishing campaigns and fraudulent GitHub repositories to infect victims. CastleRAT employs advanced evasion techniques, such as custom encryption and geolocation-based targeting.

Subscribe To Our Newsletter.

Full Name
Email