DEV-0270
Also reported as Nemesis Kitten, Storm-0270, DireFate, Yellow Dev 23, Yellow Dev 24 and 1 other name. Linked to Iran by three sources.
Reports per quarter
CVEs named in reports
- CVE-2017-0261 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-1472122
- CVE-2020-14882 KEV
- CVE-2021-1732 KEV ransomware
- CVE-2021-21972 KEV ransomware
- CVE-2021-22205 KEV ransomware
- CVE-2021-26084 KEV ransomware
- CVE-2021-26855 KEV ransomware
Show all 32 CVEs Show fewer
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-28310 KEV
- CVE-2021-31207 KEV ransomware
- CVE-2021-3120710
- CVE-2021-31979 KEV
- CVE-2021-3197961
- CVE-2021-33771 KEV
- CVE-2021-3377162
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-345239
- CVE-2021-35211 KEV ransomware
- CVE-2021-40539 KEV ransomware
- CVE-2021-440077
- CVE-2021-44228 KEV ransomware
- CVE-2021-44515 KEV
- CVE-2022-47966 KEV ransomware
- CVE-2022-47986 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor SamSam (Malware Family)
-
Magic Hound, APT 35, Cobalt Illusion, Charming Kitten
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Magic Hound, APT 35, Cobalt Illusion, Charming Kitten
-
Opsec Mistakes Reveal COBALT MIRAGE Threat Actors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Opsec Mistakes Reveal COBALT MIRAGE Threat Actors
Show all 22 reports Show fewer
-
Profiling DEV-0270- PHOSPHORUS’ ransomware operations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Profiling DEV-0270- PHOSPHORUS’ ransomware operations
-
yir-cyber-threats-report-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-report-download.pdf
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Iranian-Aligned Threat Actor
-
Log4j2 In The Wild - Iranian-Aligned Threat Actor “TunnelVision” Actively Exploiting VMware Horizon
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Log4j2 In The Wild - Iranian-Aligned Threat Actor “TunnelVision” Actively Exploiting VMware Horizon
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2022GTR
-
Iranian hackers behind Cox Media Group ransomware attack (DEV-0270)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iranian hackers behind Cox Media Group ransomware attack (DEV-0270)
-
Microsoft Digital Defense Report OCTOBER 2021
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Digital Defense Report OCTOBER 2021
Newest first. Details opens the report in Explore.