DEV-0928

First seen
2022-09-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:09:21

Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications

Context

DEV-0928 is a threat actor that has been tracked by Microsoft since September 2022. They are known for their involvement in high-volume phishing campaigns, using tools offered by DEV-1101. DEV-0928 sends phishing emails to targets and has been observed launching campaigns involving millions of emails. They also utilize evasion techniques, such as redirection to benign pages, to avoid detection.

Reports & references

  • Microsoft — Dev 1101 Enables High Volume Aitm Campaigns With Open Source Phishing Kit (report)

External references