DEV-0950

Aliases: Lace Tempest, DEV-0950, FIN11, TA505

Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
criminal
Last IoC activity
2026-07-20 21:55:12
Profile updated
2026-07-07 12:08:14

Targeted industries: financial-services technology-and-telecommunications education-and-nonprofits government-and-public-sector

Context

Lace Tempest, also known as DEV-0950, is a threat actor that exploited vulnerabilities in software such as SysAid and PaperCut to gain unauthorized access to systems. Lace Tempest is known for deploying the Clop ransomware and exfiltrating data from compromised networks.

Related threat objects

Reports & references

  • Microsoft — Raspberry Robin Worm Part Of Larger Ecosystem Facilitating Pre Ransomware Activity (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)

Attributed from

  • May 2023 Exfiltration & Wiper Activity (Truebot + FlawedGrace + MBR Killer) (campaign)

External references