DEV-1084 and MERCURY: Inside Iran’s DarkBit Ransomware Operations
ID: 252da7fd-5091-52b5-ad11-8ff7f6cd28c5
STIX ID: report--252da7fd-5091-52b5-ad11-8ff7f6cd28c5
Feed Name: Resources-2
DEV-1084 (DarkBit) is presented as a financially motivated ransomware operator but operates primarily as a destructive actor—deploying pseudo-ransomware and mass-deleting cloud resources—often in coordination with MERCURY (MuddyWater), an Iran-linked APT. The report maps their TTPs (exploitation of internet-facing services such as Log4j, use of remote access tools like Rport/Ligolo, credential theft including Azure AD Connector compromise, and deletion of shadow copies), lists observed infrastructure (e.g., IP 146.70.106.89, vatacloud.com, Mullvad VPN), and emphasizes the impactful hybrid-cloud destructive nature of their campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
