
Security researchers at tech giant Microsoft have linked multiple ransomware campaigns to DEV–0270 (also known as Nemesis Kitten), widely considered a subgroup of Iranian actor PHOSPHORUS.
According to a new write–up by Microsoft, threat actor conducts various malicious network operations on behalf of the Iranian government. Microsoft also hypothesized that some of DEV-0270’s attacks might be a form of moonlighting for personal or company-specific revenue generation based on the threat actor’s geographic and sectoral targeting.
The tech giant claimed that from a technical perspective, DEV-0270 uses exploits, particularly for recently discovered high-severity vulnerabilities, to gain access to devices. Living-off-the-land binaries (LOLBins) are also heavily utilized by DEV-0270 throughout the attack chain for credential access and discovery. According to the Microsoft advisory, this includes using the integrated BitLocker tool to encrypt files on compromised devices.
By injecting their web shell into a privileged process on a vulnerable web server, the threat actor typically gains initial access while logged in as an administrator or with system-level privileges. It then adds or creates a new user account to maintain persistence and moves laterally to other systems on the network using Impacket’s WMIExec.
Additionally, DEV-0270 was observed disabling Microsoft Defender Antivirus as one of several defensive evasion strategies used to avoid detection. According to Microsoft, the time to ransom (TTR) between initial access and the ransom note was reportedly about two days in some instances where encryption was successful.
For decryption keys, the company has been demanding USD 8,000. The actor has also been looking into other potential sources of income for their activities. For instance, in one attack that Microsoft saw, the actor posted the organization’s stolen data for sale packaged in a SQL database dump after the victim organization refused to pay the ransom.
The original text of the Microsoft advisory contains a complete list of the strategies and tactics used by DEV-0270, as well as some countermeasures against the threat.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543