Sophisticated Threat Group TAG-150 Targets Organizations

05 Sep 2025

A newly emerged, highly sophisticated cyber threat actor, TAG-150, is making waves with its advanced cyber tools and methods. Since March 2025, the group has employed a unique and intricate infrastructure to orchestrate attacks on organizations and individuals worldwide. Central to TAG-150's operations is a suite of custom malware, with CastleRAT spearheading their efforts.

A Four-Tiered Technical Approach

Recent research by Insikt Group delves into the complexities of TAG-150's infrastructure, which unfolds over four distinct layers. The structure extends from victim-facing command-and-control (C2) servers to intermediary and backup layers that obfuscate the group's malicious activities. These servers orchestrate the deployment of various malware families, such as CastleBot and CastleRAT, the latter of which comes in both Python and C variants.

CastleRAT is particularly notable for its stealth and effectiveness. The Python variant remains almost undetectable by conventional antivirus solutions, able to stealthily collect system data, manage payloads, execute commands, and self-delete. Meanwhile, the C variant offers an even richer feature set with capabilities for keylogging, clipboard hijacking, screencapturing, file transfers, persistence, and sophisticated detection evasion techniques. This makes it a formidable tool for remote control and surveillance.

Deceptive Tactics and Advanced Infrastructure

TAG-150's initial attacks frequently involve phishing exploits, employing fraudulent domains resembling trusted services or development libraries, and malicious scripts from GitHub repositories. These lures trick victims into running codes disguised as debugging tasks or software updates, boasting an infection rate of 28.7% among users interacting with them. Once a system is compromised, TAG-150 swiftly deploys further malware, connecting affected devices to their C2 network.

In efforts to evade detection and hinder law enforcement or mitigation efforts, TAG-150 employs privacy-focused technology such as Lokinet, Mega.nz, and Kleenscan. The group innovates continuously, even using Steam Community pages for C2 'dead drops,' and encapsulating command protocols within WebSockets. Their infrastructure is agile, often relocated between virtual private servers and residential IP ranges, presenting significant challenges in attribution and response.

Recommendations and Future Concerns

To counteract TAG-150’s activities, experts recommend several strategies. Blocking recognized TAG-150 infrastructure and employing updated Sigma, YARA, and Snort detection rules are essential. Filtering suspicious traffic and monitoring potential data breaches are also critical in combating this emerging threat.

The Insikt Group predicts that TAG-150 will persist in innovating and expanding its cyber arsenal, adopting new malware families and privacy-enhancing technologies to prolong its operations. Their continued activity poses a significant threat to organizations around the globe, underscoring the need for vigilant cybersecurity practices and enhanced threat detection capabilities.

  • Indicators of Compromise (IOCs):
  • CastleLoader C2 IP Addresses: 62.60.226.73, 62.60.226.211, 62.60.226.254, 79.132.130.142, 80.77.23.48, 85.158.108.135, 94.159.113.123

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
5685981
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1020273
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
440471
downloads
Geometry Dash

Geometry Dash

Latest update Geometry Dash download for free for Windows PC or Android mobile

4
539 reviews
370965
downloads

News and reviews for Desktop Windows

MachineGames Considers Sequel for Wolfenstein Series

MachineGames is contemplating a sequel to 2017's Wolfenstein: The New Colossus. As the studio head affirms commitment to the franchise, narrative challenges emerge for this story-centric series.

Read more

Ammo and Oxygen Game Reaches Key Milestone on Steam

Ammo and Oxygen, a co-op action game by Juvty Worlds, exits early access, launching Version 1.0 with new features and 20% discount. The game focuses on strategy and resource management, offering local and planned online co-op play.

Read more

Knights Crusades Strategy Game Exits Early Access

Knights Crusades by Reverie World Studios combines city-building and RTS elements in a strategy game. Set during the First Crusade, it spans Western Europe to the Holy Land, challenging players with tactical battles and political strategy. Now available on Steam with a launch discount.

Read more

Star Trucker Marks Anniversary with Special Update

Star Trucker celebrates its first anniversary with a major update and a 50% discount. The update includes enhanced peripheral support, speed checks, new cargo options, and future development plans. Available now for £10.49 until September 15.

Read more

God Save Birmingham Promises New Depth in Zombie Survival Games

God Save Birmingham offers unique medieval settings and complex survival mechanics, delivering a fresh take on the zombie genre. Players navigate ancient streets in a struggle for survival amid stunning scenery.

Read more

Tiny11 Builder Simplifies Minimal Windows 11 Installations

Tiny11 Builder, by NTDEV, offers an updated tool for streamlined Windows 11 installs, removing components like Copilot and Teams while reducing size using LZMS compression.

Read more

Windows 11 Enhances Typing with New Dash Shortcuts

Microsoft introduces keyboard shortcuts for em and en dashes in the latest Windows 11 Insider builds, improving typing efficiency for users.

Read more

Hollow Knight Silksong Faces Localization Challenge in China

Silksong's Simplified Chinese translation receives backlash, affecting its Steam reviews. Team Cherry addresses the criticism, seeking improvements after negative feedback from over 11,800 Chinese reviewers, which contrasts its global image.

Read more

Helldivers 2: Potential File Size Reduction for PC Release

Helldivers 2 may see a significant file size reduction on PC. Arrowhead Game Studios CEO addressed the issue of inflated install sizes due to duplicate assets. A fix could reduce the size from 140 GB to about 31 GB, improving ease of installation.

Read more

Prime Gaming Offers Exciting Free Games Lineup for September 2025

Prime Gaming's September lineup includes 11 free PC games featuring strategy, RPG, and indie titles. Subscribers can claim these games with an Amazon Prime subscription.

Read more