DEV-0249 is a Microsoft-tracked threat actor associated with distributing first-stage phishing payloads that can lead to human-operated ransomware intrusions. Activity linked to this actor was observed using the Sliver command-and-control framework in 2021. The available reporting supports characterization of DEV-0249 primarily as an initial-access or delivery-focused intrusion facilitator rather than a fully profiled standalone ransomware brand. High-confidence details beyond its role in phishing-enabled intrusion chains and use of Sliver are currently not available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.