DEV-0270
Aliases: Nemesis Kitten, Storm-0270
- First seen
- 2022-03-01 00:00:00
- Origin
- IR
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 11:54:44
Targeted industries: energy-and-utilities government-and-public-sector financial-services
Context
Microsoft threat intelligence teams have been tracking multiple ransomware campaigns and have tied these attacks to DEV-0270, also known as Nemesis Kitten, a sub-group of Iranian actor PHOSPHORUS. Microsoft assesses with moderate confidence that DEV-0270 conducts malicious network operations, including widespread vulnerability scanning, on behalf of the government of Iran.
Related threat objects
- APT35 (threat-actor)
Reports & references
- Microsoft — Profiling Dev 0270 Phosphorus Ransomware Operations (report)