MSTIC has not found any notable associations between this observed activity, tracked as DEV-0586, and other known activity groups. MSTIC assesses that...

Threat Actor Profile

DEV-0586

State-sponsored threat group originating from RU.

Real-Time Alerts

Actor Overview

Origin Country
RU
Incident Types
Sabotage

Suspected Victims

Ukraine

Related Threat Reports

Premium
APT Campaign Analysis - Q4 2025Dec 2025
New Tactics Observed in WildDec 2025
Infrastructure Mapping ReportDec 2025
Stay Updated

Get alerts when new intel on DEV-0586 is published.

Actor Details

Primary Name
DEV-0586
Known Aliases
Ruinous Ursa, Cadet Blizzard
Data Source
Precursor Intelligence
Need API Access?

Integrate threat actor data into your SIEM or SOAR.

View Plans →