DEV-0270 (Nemesis Kitten) is an Iran-linked subgroup of PHOSPHORUS conducting ransomware operations.
Analyst brief
DEV-0270 (Nemesis Kitten) is a sub-group of the Iranian state-linked actor PHOSPHORUS, primarily involved in ransomware campaigns. The actor gains initial access through widespread vulnerability scanning and exploitation. Defenders should prioritize patching internet-facing systems and implement robust backup and recovery procedures to mitigate ransomware impact.
DEV-0270
Nemesis KittenStorm-0270
unknown
Microsoft threat intelligence teams have been tracking multiple ransomware campaigns and have tied these attacks to DEV-0270, also known as Nemesis Kitten, a sub-group of Iranian actor PHOSPHORUS. Microsoft assesses with moderate confidence that DEV-0270 conducts malicious network operations, including widespread vulnerability scanning, on behalf of the government of Iran.