Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Also known as: DEV-0270, Nemesis Kitten, DireFate, Yellow Dev 23, Yellow Dev 24, Lord Nemesis, Storm-0270
A subgroup of Magic Hound, APT 35, Cobalt Illusion, Charming Kitten . ( Microsoft ) Microsoft threat intelligence teams have been tracking multiple ransomware campaigns and have tied these attacks to DEV-0270, also known as Nemesis Kitten, a sub-group of Iranian actor PHOSPHORUS. Microsoft assesses with moderate confidence that DEV-0270 conducts malicious network operations, including widespread vulnerability scanning, on behalf of the government of Iran. However, judging from their geographic and sectoral targeting, which often lacked a strategic value for the regime, we assess with low confidence that some of DEV-0270’s ransomware attacks are a form of moonlighting for personal or company-specific revenue generation.
No exploited CVEs have been attributed to this threat actor yet.
Browse CVE Database