DEV-0365 is a Microsoft-tracked cybercriminal subgroup associated with DEV-0193, also known as Trickbot LLC. It functions primarily as infrastructure-as-a-service for other criminal operators, most notably providing Cobalt Strike Beacon as a service and maintaining command-and-control infrastructure used across multiple intrusion sets. The cluster is linked to broader human-operated ransomware activity through infrastructure overlaps with campaigns involving BazaLoader, Trickbot, and Conti-associated operations. DEV-0365 is not best characterized as a standalone ransomware brand or intrusion crew; rather, it appears to support other financially motivated actors by supplying and managing shared post-exploitation infrastructure. Observed activity tied to this cluster includes operation of Cobalt Strike infrastructure used after initial compromise, enabling follow-on credential theft, lateral movement, and broader hands-on-keyboard intrusion activity by downstream actors. Infrastructure associated with DEV-0365 has also overlapped with exploitation campaigns such as those using CVE-2021-40444, where custom Cobalt Strike Beacon loaders were delivered after document-based initial access. The group’s role in the cybercriminal ecosystem aligns with service-provider behavior inside the ransomware-as-a-service landscape: supplying tooling and infrastructure that can be reused by affiliates or related operators conducting post-compromise operations and, in some cases, ransomware deployment. Known association is strongest with DEV-0193/Trickbot LLC; no separate nation-state attribution is established on the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.