Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft Threat Intelligence reported on November 17, 2022, that a cybercrime group it called DEV-0569 used deceptive ads, phishing and fake software installers to deliver BATLOADER and other malware. Some of the infection chains Microsoft observed led to human-operated Royal ransomware attacks; the report did not say every infection resulted in Royal. These are observations from campaigns in August–October 2022, not a report of activity in 2026. Microsoft’s page was updated in April 2023 to say it now tracks DEV-0569 as Storm-0569.

How did DEV-0569 deliver Royal ransomware?

Microsoft described a changing mix of social engineering and malicious downloads. The actor’s lures posed as legitimate software, installers or updates, while links and files were hosted on attacker-created domains or, in some cases, abused legitimate repositories. BATLOADER was among the malware used in the observed infection chains.

  • Malvertising: Malicious ads sent people toward fake software-download pages. In a campaign identified in late October 2022, Google Ads led to a traffic distribution system that could redirect selected visitors to a malicious BATLOADER site.
  • Fake pages and comments: Microsoft reported fake forum pages and blog comments used to promote malicious downloads.
  • Phishing: Emails and contact-form messages directed targets to malicious links or downloads. In a campaign observed in September 2022, messages submitted through organizations’ contact forms impersonated a national financial authority. Replies led targets to BATLOADER.
  • Installer behavior: BATLOADER used MSI Custom Actions to launch malicious PowerShell activity or batch scripts.

Microsoft said scripts in the contact-form campaign could download Gozi and Vidar Stealer, among other possible payloads. It also described links between some DEV-0569 infection chains and human-operated attacks deploying Royal ransomware. The report therefore documents multiple outcomes—not a one-to-one path from every deceptive download to a Royal infection. Microsoft assessed that the group could be an attractive access broker, but framed that as an assessment rather than a confirmed role.

What dates and actor name apply?

The report’s observations cover campaigns from August to October 2022, including the September contact-form activity and the late-October Google Ads campaign. Microsoft published its account on November 17, 2022. Those dates describe the activity covered in that report and should not be read as a current frequency or a claim of ongoing 2026 operations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft used DEV-0569 as the designation for the emerging activity cluster in the 2022 report. An April 2023 update to the report says Microsoft tracks the actor as Storm-0569. The original name is relevant when referring to the 2022 findings; Storm-0569 is the later designation.

What does Microsoft recommend to protect against Royal ransomware phishing?

Microsoft’s recommendations address different points in the delivery chain. They are layers of defense, not guarantees that an attack will be stopped.

Stage Microsoft-named controls Purpose
Web links and downloads Microsoft Defender SmartScreen; Microsoft Defender Antivirus; Microsoft Defender for Endpoint SmartScreen can help warn about malicious or suspicious sites and downloads. Defender Antivirus and Defender for Endpoint provide endpoint protection and detection capabilities.
Email and collaboration messages Microsoft Defender for Office 365; Safe Links; mail-flow rules These controls can help detect, inspect or block malicious links and messages, including links shared through email and collaboration services.
Endpoint behavior Attack-surface-reduction rules; Defender Antivirus; Defender for Endpoint These measures can restrict risky behaviors or help identify and respond to suspicious activity, including malware execution and ransomware techniques.
Organizational exposure Least privilege; credential hygiene; user awareness and reporting Limiting privileges can reduce what a compromised account or process can do. Strong credential practices and training can make deceptive messages less likely to lead to access.

Microsoft specifically reported NSudo being used in attempts to disable antivirus solutions. That makes endpoint protections and limiting unnecessary privileges relevant alongside controls that address the initial link or download. Staff should know how to report suspicious messages and should avoid opening unexpected installer or update links, even when the message appears to come from a familiar service or organization.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What Microsoft’s warning establishes—and what it does not

Microsoft Threat Intelligence’s November 17, 2022 report documents delivery methods, malware payloads and links between some infection chains and Royal ransomware attacks. It does not provide a named prevalence or impact statistic, establish that all DEV-0569 infections deployed Royal, or show that the described campaigns continued into 2026. Microsoft wrote in that report: “DEV-0569 will likely continue to rely on malvertising and phishing to deliver malware payloads.” That was the company’s assessment at the time, not a current activity update.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read Microsoft Threat Intelligence’s report, “DEV-0569 finds new ways to deliver Royal ransomware, various payloads”.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.