Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-07

GrayBravo

Also known as:TAG-150

As of 2026-09-20, GrayBravo is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning malware. Also known as TAG-150. ATT&CK coverage spans 36 techniques across 11 tactics in 2 of 2 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1082 (System Information Discovery), T1113 (Screen Capture).

Tracked threats
21 high · 1 medium
First seen
2026-07-23
Last seen
2026-09-20
ATT&CK techniques
36across 2 of 2 threats
Related CVEs
0None referenced
2 tracked threat(s) · Categories: MALWARE

Activity timeline

GrayBravo appears in 2 tracked threats between and ; the busiest month was 2026-07 with 1 report.

ATT&CK techniques observed

36 techniques observed across 2 of 2 tracked threats · Stealth (formerly Defense Evasion) (10), Command and Control (8), Execution (6), Collection (3), Initial Access (3), Discovery (2)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 2 of 2 tracked threats
  • T1113 Screen Capture — Collectionobserved in 2 of 2 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1620 Reflective Code Loading — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1027.007 Dynamic API Resolution — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
  • T1053 Scheduled Task/Job — Persistenceobserved in 1 of 2 tracked threats
  • T1055 Process Injection — Privilege Escalationobserved in 1 of 2 tracked threats
  • T1055.012 Process Injection: Process Hollowing — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
  • T1056 Input Capture — Collectionobserved in 1 of 2 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 1 of 2 tracked threats
  • T1059.001 PowerShell — Executionobserved in 1 of 2 tracked threats
  • T1059.003 Windows Command Shell — Executionobserved in 1 of 2 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 1 of 2 tracked threats

Tracked threats