Saturday, 6 September, 2025
TAG-150 Hackers Deploy Self-Developed Malware Families to Attack Organizations

TAG-150, a sophisticated threat actor active since March 2025, has developed and deployed multiple self-created malware families, including CastleLoader, CastleBot, and the recently identified CastleRAT—a remote access trojan. These attacks primarily utilize Cloudflare-themed phishing campaigns and fraudulent GitHub repositories to infect victims. CastleRAT employs advanced evasion techniques, such as custom encryption and geolocation-based targeting.
Read full story at Cybersecurity News