DEV-0950
Aliases: Lace Tempest, DEV-0950, FIN11, TA505
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- criminal
- Last IoC activity
- 2026-07-20 21:55:12
- Profile updated
- 2026-07-07 12:08:14
Targeted industries: financial-services technology-and-telecommunications education-and-nonprofits government-and-public-sector
Context
Lace Tempest, also known as DEV-0950, is a threat actor that exploited vulnerabilities in software such as SysAid and PaperCut to gain unauthorized access to systems. Lace Tempest is known for deploying the Clop ransomware and exfiltrating data from compromised networks.
Related threat objects
Reports & references
- Microsoft — Raspberry Robin Worm Part Of Larger Ecosystem Facilitating Pre Ransomware Activity (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
Attributed from
- May 2023 Exfiltration & Wiper Activity (Truebot + FlawedGrace + MBR Killer) (campaign)