Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors DEV-0928

Description

DEV-0928 is a threat actor that has been tracked by Microsoft since September 2022. They are known for their involvement in high-volume phishing campaigns, using tools offered by DEV-1101. DEV-0928 sends phishing emails to targets and has been observed launching campaigns involving millions of emails. They also utilize evasion techniques, such as redirection to benign pages, to avoid detection.

AI Analysis

· 1 week ago

Executive Summary

DEV-0928 is a recently identified threat actor tracked by Microsoft since September 2022. They primarily engage in large-scale phishing campaigns, leveraging tools from DEV-1101 to target numerous sectors through high-volume email distribution and basic evasion techniques.

Goals & Targeting

DEV-0928's strategic objectives likely include data theft and financial gain, given their reliance on phishing for large-scale campaigns. Their targeting profile is not sector-specific but rather volume-focused, potentially seeking to compromise any organization within their reach that offers viable opportunities for exploitation. This broad approach allows them to operate across industries with significant email traffic.

Enhanced Description

DEV-0928 has emerged as a significant player in the cyber threat landscape, focusing on extensive phishing operations. These campaigns are characterized by their use of toolkits provided by another actor, DEV-1101, enabling them to send millions of phishing emails. The group's strategy involves not only distributing malicious links but also employing diversion tactics to redirect victims to benign pages, thereby evading detection. While DEV-0928 has not been conclusively linked to specific sectors or countries yet, their broad targeting approach suggests a focus on maximizing reach and potential impact across various industries.

Key Capabilities

  • High-volume phishing campaigns
  • Email spoofing and spam distribution tools
  • Redirection techniques to evade detection

MITRE ATT&CK Tactics

Initial Access

ATT&CK Techniques

T1566.002 - Phishing via Email Attachment (Spear-Phishing)

Software / Tooling

Email spoofing tools
DEV-1101-provided kits

Campaigns & Victims

DEV-0928's campaigns are marked by their volume and use of phishing tactics. Their operations since September 2022 have targeted a wide range of sectors, suggesting an intent to maximize opportunities rather than focusing on specific industries. While exact campaign specifics are limited, the group demonstrates scalability in their approach.

IOC Patterns

  • Spear-phishing emails with malicious links

Recommended Actions

  • Implement robust email filtering and anti-phishing solutions
  • Conduct regular employee training to recognize phishing attempts
  • Monitor network traffic for spikes indicating large-scale campaigns

Suggested Tags

Phishing
Sectors: Multiple
Volume-Based Attacks

Confidence Assessment

Low confidence due to limited details on TTPs, objectives, and specific targets beyond their phishing activities. Additional data is needed for a comprehensive understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Phishing
Sectors: Multiple
Volume-Based Attacks

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.