Actors Insights|Latest update24/07/2026

DEV-0133

Named by MicrosoftSuspected state sponsor: Islamic Republic of Iran

DEV-0133 is a Microsoft temporary staging designation used to track Iranian threat actor activity linked to the July 2022 destructive cyberattack campaign against Albanian government infrastructure. Microsoft used the DEV prefix as an early-stage identifier before sufficient attribution evidence was gathered for a permanent name. DEV-0133 was one of at least four Iranian actor groups Microsoft identified as participating in the coordinated Albania operation, which involved distinct phases of initial access, intelligence collection, and destructive wiper deployment. The designation covers one specific phase or operational role within the broader attack that was attributed to Iranian state actors including IRGC and MOIS-linked groups.

First Seen:Jul 2022
Last Seen:Sep 2022
Indexed Reports:0
Public IOCs:0
Cluster: Unclassified
also known as:
DEV-0133 (Microsoft)

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.