DEV-0270

Aliases: Nemesis Kitten, Storm-0270

First seen
2022-03-01 00:00:00
Origin
IR
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:54:44

Targeted industries: energy-and-utilities government-and-public-sector financial-services

Context

Microsoft threat intelligence teams have been tracking multiple ransomware campaigns and have tied these attacks to DEV-0270, also known as Nemesis Kitten, a sub-group of Iranian actor PHOSPHORUS. Microsoft assesses with moderate confidence that DEV-0270 conducts malicious network operations, including widespread vulnerability scanning, on behalf of the government of Iran.

Related threat objects

Reports & references

  • Microsoft — Profiling Dev 0270 Phosphorus Ransomware Operations (report)

External references