ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Multiple ransomware campaigns linked to Iranian threat actor DEV-0270

Security researchers at tech giant Microsoft have linked multiple ransomware campaigns to DEV–0270 (also known as Nemesis Kitten), widely considered a subgroup of Iranian actor PHOSPHORUS.

 

According to a new write–up by Microsoft, threat actor conducts various malicious network operations on behalf of the Iranian government. Microsoft also hypothesized that some of DEV-0270’s attacks might be a form of moonlighting for personal or company-specific revenue generation based on the threat actor’s geographic and sectoral targeting.

 

The tech giant claimed that from a technical perspective, DEV-0270 uses exploits, particularly for recently discovered high-severity vulnerabilities, to gain access to devices. Living-off-the-land binaries (LOLBins) are also heavily utilized by DEV-0270 throughout the attack chain for credential access and discovery. According to the Microsoft advisory, this includes using the integrated BitLocker tool to encrypt files on compromised devices.

 

By injecting their web shell into a privileged process on a vulnerable web server, the threat actor typically gains initial access while logged in as an administrator or with system-level privileges. It then adds or creates a new user account to maintain persistence and moves laterally to other systems on the network using Impacket’s WMIExec.

 

Additionally, DEV-0270 was observed disabling Microsoft Defender Antivirus as one of several defensive evasion strategies used to avoid detection. According to Microsoft, the time to ransom (TTR) between initial access and the ransom note was reportedly about two days in some instances where encryption was successful.

 

For decryption keys, the company has been demanding USD 8,000. The actor has also been looking into other potential sources of income for their activities. For instance, in one attack that Microsoft saw, the actor posted the organization’s stolen data for sale packaged in a SQL database dump after the victim organization refused to pay the ransom.

 

The original text of the Microsoft advisory contains a complete list of the strategies and tactics used by DEV-0270, as well as some countermeasures against the threat.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543