DEV-0569

Aliases: Storm-0569

Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:11:01

Targeted industries: education-and-nonprofits healthcare-and-pharmaceutical manufacturing technology-and-telecommunications

Targeted regions: country_code:us country_code:br

Context

DEV-0569, also known as Storm-0569, is a threat actor group that has been observed deploying the Royal ransomware. They utilize malicious ads and phishing techniques to distribute malware and gain initial access to networks. The group has been linked to the distribution of payloads such as Batloader and has forged relationships with other threat actors. DEV-0569 has targeted various sectors, including healthcare, communications, manufacturing, and education in the United States and Brazil.

Reports & references

  • Microsoft — Dev 0569 Finds New Ways To Deliver Royal Ransomware Various Payloads (report)

External references