DEV-0133
Named by MicrosoftSuspected state sponsor: Islamic Republic of IranDEV-0133 is a Microsoft temporary staging designation used to track Iranian threat actor activity linked to the July 2022 destructive cyberattack campaign against Albanian government infrastructure. Microsoft used the DEV prefix as an early-stage identifier before sufficient attribution evidence was gathered for a permanent name. DEV-0133 was one of at least four Iranian actor groups Microsoft identified as participating in the coordinated Albania operation, which involved distinct phases of initial access, intelligence collection, and destructive wiper deployment. The designation covers one specific phase or operational role within the broader attack that was attributed to Iranian state actors including IRGC and MOIS-linked groups.
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.