Actors Insights|Latest update04/07/2026

Storm-0270

Named by MicrosoftSuspected state sponsor: Islamic Republic of Iran

Storm-0270 is Microsoft's formal designation for the Iranian IRGC-linked ransomware subgroup previously tracked as DEV-0270, operating within the broader Nemesis Kitten cluster. The group gained notoriety for using Windows BitLocker Drive Encryption as a ransomware tool in attacks against US organizations in 2022, combined with data theft and extortion. Storm-0270's operations straddle the line between financially motivated ransomware and state-directed disruption, reflecting the Iranian practice of using cyber criminal-style activity to maintain plausible deniability while advancing national objectives.

This threat actor previously was known as DEV-0270
First Seen:Aug 2022
Last Seen:Sep 2022
Indexed Reports:1
Public IOCs:2
Cluster: Nemesis KittenMisp: DEV-0270
also known as:
Nemesis Kitten (CrowdStrike)Storm-0270 (Microsoft)DEV-0270 (Microsoft)

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.