White Dev 89 is an unattributed cyber threat actor associated with opportunistic malware delivery through malvertising campaigns. The actor has been observed distributing trojanized versions of legitimate remote access, conferencing, and VPN software to infect victims. Activity attributed to this cluster includes delivery of Cobalt Strike and infrastructure overlaps with QakBot-related campaigns, indicating use of commodity criminal tooling and access-broker or malware-delivery tradecraft rather than a clearly established nation-state mission. Observed behavior is consistent with initial access operations that rely on deceptive software lures and follow-on post-compromise tooling. Publicly available high-confidence reporting does not establish a definitive geographic origin, stable victimology, or a broader alias set beyond White Dev 89.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.