DEV-0450 is a Microsoft-tracked cybercriminal activity cluster associated with distributing Qakbot malware as part of intrusion chains that have led to ransomware attacks. The group is specifically linked to a “presidents”-themed Qakbot campaign style that used names of American presidents in its operations. DEV-0450 functions as an upstream access and malware distribution actor within the broader ransomware ecosystem rather than being identified as a standalone ransomware brand or operator. The cluster is assessed as a Qakbot distributor whose infections have enabled downstream ransomware deployment by other affiliates. Reported follow-on actors tied to these intrusion chains include DEV-0216, DEV-0506, and DEV-0826, illustrating DEV-0450’s role in supplying initial footholds or malware access that is later monetized through hands-on-keyboard ransomware activity. This placement is consistent with the ransomware-as-a-service ecosystem, where specialized actors separate malware delivery and initial compromise from later-stage privilege escalation, lateral movement, data theft, and extortion. High-confidence reporting directly supports DEV-0450’s involvement in initial access through malware distribution. Because the available facts do not attribute specific victim geographies, industry verticals, country of origin, or distinct post-compromise tradecraft to DEV-0450 itself, those attributes remain unconfirmed. The actor is best characterized as a financially motivated cybercriminal distributor in the Qakbot-enabled ransomware access chain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.