Actors Insights|Latest update27/08/2026

DEV-1084

Named by MicrosoftSuspected state sponsor: Islamic Republic of Iran

DEV-1084 is Microsoft's temporary designation for a MuddyWater subgroup responsible for the March 2023 destructive attack against Israeli organizations using DarkBit ransomware. Microsoft later formally named this subgroup Storm-1084. The attack followed an intrusion attributed to Mango Sandstorm (MuddyWater), in which DEV-1084 leveraged access established by the parent cluster to deploy the DarkBit payload — effectively combining MuddyWater's espionage access with a destructive wiper-ransomware capability, resulting in significant disruption to affected Israeli organizations.

This threat actor's name is changed to Storm-1084
First Seen:Mar 2023
Last Seen:Apr 2023
Indexed Reports:0
Public IOCs:0
Cluster: MuddyWaterMisp: Storm-1084
also known as:
DEV-1084 (Microsoft)Storm-1084 (Microsoft)

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.