Also known as: Nemesis Kitten, Storm-0270
Microsoft threat intelligence teams have been tracking multiple ransomware campaigns and have tied these attacks to DEV-0270, also known as Nemesis Kitten, a sub-group of Iranian actor PHOSPHORUS. Microsoft assesses with moderate confidence that DEV-0270 conducts malicious network operations, including widespread vulnerability scanning, on behalf of the government of Iran.
Executive Summary
DEV-0270, also known as Nemesis Kitten or Storm-0270, is a sub-group of the Iranian state-sponsored actor PHOSPHORUS. Microsoft has linked this threat group to ransomware campaigns and malicious network activities, assessing with moderate confidence that they operate on behalf of the Iranian government.
Goals & Targeting
DEV-0270's primary goals appear to be furthering Iranian political and strategic interests through cyberattacks. This includes targeting critical infrastructure sectors such as healthcare, education, and non-profit organizations, where the impact of an attack can be significant. Their activities suggest a focus on financial gain through ransomware operations, though their state-sponsored nature indicates a potential dual-use for geopolitical leverage.
Enhanced Description
DEV-0270 is a subsection of the broader PHOSPHORUS group, known for its state-sponsored cyber activities. The group has been involved in various malicious operations, including ransomware campaigns and network intrusions. Microsoft's analysis indicates that DEV-0270 conducts these activities under the direction or support of the Iranian government, as part of a broader effort to achieve geopolitical objectives through cyber means. Their techniques include widespread vulnerability scanning, which suggests a focus on identifying and exploiting vulnerable targets across multiple sectors.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
DEV-0270 has been linked to multiple ransomware campaigns targeting sectors with significant societal impact. Their operations suggest a methodical approach, leveraging phishing and network scanning to penetrate targets. Notable past operations include attacks on healthcare facilities, which disrupt critical services and cause widespread panic.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis by Microsoft provides moderate confidence in the association of DEV-0270 with Iranian state activities. Additional confirmation from independent sources would strengthen this assessment.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics