DEV-0928
- First seen
- 2022-09-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:09:21
Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications
Context
DEV-0928 is a threat actor that has been tracked by Microsoft since September 2022. They are known for their involvement in high-volume phishing campaigns, using tools offered by DEV-1101. DEV-0928 sends phishing emails to targets and has been observed launching campaigns involving millions of emails. They also utilize evasion techniques, such as redirection to benign pages, to avoid detection.
Reports & references
- Microsoft — Dev 1101 Enables High Volume Aitm Campaigns With Open Source Phishing Kit (report)