Parsing: enabled
Known RaaS
Description
DevMan is a ransomware variant first observed in April 2025. It is a customized derivative of the DragonForce family, leveraging attacker-operated infrastructure for double-extortion, where both data theft and encryption are employed to pressure victims. The threat is highly organized, targeting sectors such as technology, construction, public services, healthcare, and consumer services across Asia, Africa, and Europe.
External Analysis4
| External Analysis |
|---|
| https://medium.com/@anyrun/devman-ransomware-analysis-of-new-dragonforce-variant-ede707fd30b1 |
| https://www.broadcom.com/support/security-center/protection-bulletin/devman-a-new-dragonforce-ransomware-variant |
| https://www.watchguard.com/wgrd-security-hub/ransomware-tracker/devman |
| https://www.hivepro.com/threat-advisory/devman-ransomware-is-a-new-derivative-of-the-dragonforce-family/ |
Ransom notes1
Tox1
| Tox |
|---|
| 9D97F166730F865F793E2EA07B173C742A6302879DE1B0BBB03817A5A04B572FBD82F984981D |