DEV-0464 is a cybercriminal activity cluster tracked as a distributor of Qakbot and other malware, including SquirrelWaffle, within the broader ransomware-as-a-service ecosystem. The actor is associated with malware delivery operations that provide upstream access and infection chains later used by ransomware affiliates. In observed campaigns, DEV-0464 distributed the “TR” variant of Qakbot and rapidly incorporated exploitation of CVE-2022-30190, the Microsoft Support Diagnostic Tool vulnerability, indicating an ability to quickly operationalize newly disclosed initial-access techniques. DEV-0464’s role is best characterized as an access and malware distribution node rather than a standalone ransomware brand. Infections attributed to this cluster have been linked to downstream ransomware activity by multiple affiliates, demonstrating its function in enabling later-stage intrusions and monetization by other criminal actors. Its tradecraft directly supports early intrusion phases, especially malware delivery and foothold establishment, and indirectly supports subsequent hands-on-keyboard ransomware operations conducted by partner or follow-on actors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.