Attribution
Iran state-nexus, IRGC-affiliated. Microsoft attributes DEV-0270 as a sub-group of PHOSPHORUS (Mint Sandstorm); Secureworks tracks the same activity as Cobalt Mirage. In Sept 2022 the US DoJ indicted and Treasury OFAC sanctioned individuals tied to the front companies Najee Technology Hooshmand Fater, Afkar System, and Secnerd/Lifeweb, stating they were affiliated with the IRGC. Confidence: high for Iran/IRGC nexus (multi-source: Microsoft, Secureworks, US Government indictment + sanctions).
Motivation
Dual mission: state-directed espionage/access operations plus opportunistic, financially-motivated ransomware and disruption. Some ransomware activity appears to be 'moonlighting' for personal/company revenue rather than strategic regime targeting.