DEV-0230
DEV-0230 is a Microsoft-tracked cybercriminal ransomware affiliate described as one of the most prolific and successful Conti affiliates. Microsoft states that DEV-0230 was responsible for developing the leaked "Conti Manual" published in August 2021. The actor also developed and deployed the FiveHands and HelloKitty ransomware payloads, and later shifted to deploying QuantumLocker. Microsoft reports that DEV-0230 often gained initial access via BazaLoader. Based on the provided content, DEV-0230 operated within the broader ransomware-as-a-service ecosystem around Conti and related payloads.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
5 malware families attributed to this actor across reporting.
Recent activity
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.