DEV-0464 is a Microsoft-tracked cybercriminal activity group identified as a Qakbot distributor. Microsoft reported that DEV-0464 distributes the “TR” Qakbot and other malware including SquirrelWaffle, and that infections associated with DEV-0464 have led to ransomware deployments by affiliates such as DEV-0216, DEV-0506, and DEV-0826. Microsoft also stated that DEV-0464 rapidly adopted exploitation of the Microsoft Support Diagnostic Tool vulnerability CVE-2022-30190 in its campaigns. The provided content does not attribute DEV-0464 to a nation state and does not provide additional confirmed aliases or subgroup information beyond the DEV-0464 designation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.