DEV-0928 is a threat actor that has been tracked by Microsoft since September 2022. They are known for their involvement in high-volume phishing campaigns, using tools offered by DEV-1101. DEV-0928 sends phishing emails to targets and has been observed launching campaigns involving millions of emails. They also utilize evasion techniques, such as redirection to benign pages, to avoid detection.
Executive Summary
DEV-0928 is a recently identified threat actor tracked by Microsoft since September 2022. They primarily engage in large-scale phishing campaigns, leveraging tools from DEV-1101 to target numerous sectors through high-volume email distribution and basic evasion techniques.
Goals & Targeting
DEV-0928's strategic objectives likely include data theft and financial gain, given their reliance on phishing for large-scale campaigns. Their targeting profile is not sector-specific but rather volume-focused, potentially seeking to compromise any organization within their reach that offers viable opportunities for exploitation. This broad approach allows them to operate across industries with significant email traffic.
Enhanced Description
DEV-0928 has emerged as a significant player in the cyber threat landscape, focusing on extensive phishing operations. These campaigns are characterized by their use of toolkits provided by another actor, DEV-1101, enabling them to send millions of phishing emails. The group's strategy involves not only distributing malicious links but also employing diversion tactics to redirect victims to benign pages, thereby evading detection. While DEV-0928 has not been conclusively linked to specific sectors or countries yet, their broad targeting approach suggests a focus on maximizing reach and potential impact across various industries.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
DEV-0928's campaigns are marked by their volume and use of phishing tactics. Their operations since September 2022 have targeted a wide range of sectors, suggesting an intent to maximize opportunities rather than focusing on specific industries. While exact campaign specifics are limited, the group demonstrates scalability in their approach.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence due to limited details on TTPs, objectives, and specific targets beyond their phishing activities. Additional data is needed for a comprehensive understanding.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics