Threat Actor
TAG-150
- First Reported
- Apr 21, 2026
- Latest Reported
- Jul 15, 2026
Reported Context (2)
- The article attributes the analyzed ClickFix infection chain to this group, describes it as active since March 2025, and associates it with NightshadeC2. eSentire Details TAG-150’s ClickFix Chain Delivering DinDoor, DenoRAT and NightshadeC2
- JUMPSEC reportedly attributed serialmenot[.]com to TAG-150 as a CastleLoader backend. The conclusion refers to TAG-150/GrayBravo and tentatively compares the financial-services lure with its activity. DinDoor Backdoor Abuses Deno Runtime; Researchers Identify 20 Active C2 Servers
Malware (7)
People (1)
Threat Actors (2)
MITRE ATT&CK (32)
Vendors (19)
Products (104)
Tools (7)
Industries (2)
Countries (6)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.