Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors DEV-0569

Also known as: Storm-0569

Description

DEV-0569, also known as Storm-0569, is a threat actor group that has been observed deploying the Royal ransomware. They utilize malicious ads and phishing techniques to distribute malware and gain initial access to networks. The group has been linked to the distribution of payloads such as Batloader and has forged relationships with other threat actors. DEV-0569 has targeted various sectors, including healthcare, communications, manufacturing, and education in the United States and Brazil.

AI Analysis

· 1 week ago

Executive Summary

DEV-0569, also known as Storm-0569, is a threat actor group specializing in ransomware deployments, leveraging malicious ads and phishing techniques. They collaborate with other groups and target sectors including healthcare, communications, manufacturing, and education in the United States and Brazil.

Goals & Targeting

Dev-0569's primary motivation appears to be financial gain through ransom operations. Their targeting of healthcare, manufacturing, and education sectors suggests an interest in verticals where operational disruption can yield high payouts. The focus on both the U.S. and Brazil indicates a geographically diverse but region-specific approach.

Enhanced Description

DEV-0569 operates by distributing ransomware through恶意广告 (malvertising) campaigns and phishing techniques to gain network access. The group has notably deployed the Royal ransomware alongside payloads like Batloader, which suggests a focus on multi-stage attack vectors. Their activities indicate a capability for persistence and lateral movement within networks, potentially utilizing tools associated with other advanced threat groups.

Key Capabilities

  • Malware distribution via malvertising
  • Phishing email campaigns
  • Ransomware deployment (Royal)
  • Collaborations with other threat actors

MITRE ATT&CK Tactics

Ransomware
Initial Access
Defense Evasion
Credential Access
Discovery

ATT&CK Techniques

T1566.002
T1485.002
T1574
T1569.001
T1055.003

Software / Tooling

Royal Ransomware
Batloader
Mimikatz-like credential dumping tools
Cobalt Strike (potential)

Campaigns & Victims

Campaigns by DEV-0569 often involve multi-vector attacks, combining malvertising with targeted phishing. Their operations typically aim for high-value targets within critical infrastructure sectors. Notable past campaigns include healthcare-focused deployments in late 2023.

IOC Patterns

  • Malicious ad network traffic
  • Script-based malware delivery
  • Cobalt Strike-like C2 communications
  • Anomalous RDP sessions

Recommended Actions

  • Enhance email filtering to block phishing attempts.
  • Monitor for malvertising campaigns on public websites.
  • Secure remote access points, such as RDP, with multi-factor authentication.
  • Implement network monitoring for unusual lateral movement patterns.

Suggested Tags

Ransomware
Malvertising
Phishing
Healthcare
Manufacturing

Confidence Assessment

Low confidence due to limited data on primary motivation and exact TTPs. Further analysis could validate their collaboration with other groups and toolset.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Phishing
Malvertising
Healthcare
Manufacturing

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.