Nemesis Kitten is an Iranian state-nexus, IRGC-affiliated intrusion cluster tracked by Microsoft as DEV-0270 (later Storm-0270), a sub-group of PHOSPHORUS/Mint Sandstorm, and by Secureworks as Cobalt Mirage. The activity is operated through Iranian contractor front companies (Najee Technology Hooshmand Fater, Afkar System, and Secnerd/Lifeweb). The group is highly opportunistic, mass-scanning the internet for vulnerable internet-facing systems and rapidly weaponizing newly disclosed CVEs, then deploying ransomware or disk-encryption for disruption and extortion alongside espionage tasking.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
DEV-0270/Nemesis Kitten emerged around 2020-2021 as part of Iran's PHOSPHORUS ecosystem and was one of the earliest state-linked actors to operationalize newly disclosed vulnerabilities at scale. Microsoft assessed the group is run by a company operating under the public aliases Secnerd and Lifeweb, linked to Najee Technology Hooshmand Fater in Karaj, Iran; Secureworks additionally connected Cobalt Mirage to Najee Technology, Afkar System, and Secnerd. Initial access is overwhelmingly opportunistic: exploitation of Microsoft Exchange (ProxyShell/ProxyLogon), Fortinet FortiOS SSL-VPN flaws (e.g., CVE-2018-13379), and Log4Shell (Log4j) in exposed applications such as VMware Horizon. Post-exploitation the group relies heavily on LOLBins for discovery and credential access, uses web shells and tools like Fast Reverse Proxy (FRP), and abuses built-in Windows BitLocker (via setup.bat) to encrypt servers and DiskCryptor on workstations to render hosts inoperable and extort victims. Secureworks documented Cobalt Mirage running two intrusion sets: 'Cluster A' opportunistic BitLocker ransomware for financial gain, and 'Cluster B' more targeted intrusions for intelligence collection. In September 2022 the US DoJ unsealed charges against three Iranian nationals and Treasury OFAC sanctioned ten individuals and two entities (Najee Technology and Afkar System) affiliated with the IRGC over ransomware attacks affecting US critical infrastructure, healthcare, transportation, local government, and organizations across the US, UK, Israel, Russia, and elsewhere. Victimology is predominantly opportunistic and global (notably US and other Western targets), with sectoral/geographic selection that frequently lacked strategic value to the regime — consistent with revenue-driven moonlighting. Activity continued under Microsoft's Storm-0270 designation into 2023-2024, with the broader PHOSPHORUS/Mint Sandstorm ecosystem remaining active. MENA relevance: This is an Iran-origin (Tehran-directed) actor, so it is a MENA-nexus threat by origin. Direct Israel targeting is plausible and partially corroborated — Israel appears among the geographies named in the 2022 US sanctions/indictment reporting as affected by these Iranian ransomware operations — but the actor's dominant, well-documented victimology is opportunistic US/global exploitation rather than deliberate Israel-focused campaigns. The existing RaqibCTI 'Israel' country tag is defensible as an affected-victim geography but should be treated as opportunistic collateral, not a primary/strategic targeting pattern; the stronger MENA linkage is the actor's Iran/IRGC origin.
+23 more relationships — see the relationships browser.