Devman

Compare
devman logo
Parsing: enabled Known RaaS

View crypto

Description

DevMan is a ransomware variant first observed in April 2025. It is a customized derivative of the DragonForce family, leveraging attacker-operated infrastructure for double-extortion, where both data theft and encryption are employed to pressure victims. The threat is highly organized, targeting sectors such as technology, construction, public services, healthcare, and consumer services across Asia, Africa, and Europe.

External Analysis4
External Analysis
https://medium.com/@anyrun/devman-ransomware-analysis-of-new-dragonforce-variant-ede707fd30b1
https://www.broadcom.com/support/security-center/protection-bulletin/devman-a-new-dragonforce-ransomware-variant
https://www.watchguard.com/wgrd-security-hub/ransomware-tracker/devman
https://www.hivepro.com/threat-advisory/devman-ransomware-is-a-new-derivative-of-the-dragonforce-family/
Tox1
Tox
9D97F166730F865F793E2EA07B173C742A6302879DE1B0BBB03817A5A04B572FBD82F984981D
Urls1
Url
Status
Screen
Uptime 30d
Health
http://qljmlmp4psnn3wqskkf3alqquatymo6hntficb4rhq5n76kuogcv7zyd.onion/ Down Screen
0%
Activity (interactive) 49
Activity charts
Posts49
Date Title Description Screen
NSSF KENYA(negotiation started) /nssf.zip - first samle /nssfwriteup.html - writeup
DHL THAILAND
lantro.com
dmbarone.com
Gobierno del Estado de Colima
SAVE THIS PGP MESSAGE
www.nijar.es
www.paragonradiology.com
netstar.co.za
NSSF KENYA(negotiation started)
NSSF KENYA
TBD KOREA
TBD HONK KONG
TBD GREECE
TOHO-CO
TBD KENYA
piriou.vn
tvgoiania.com.br
Pienaar Brothers (DevMan Ransomware)
Victim from Japan
dailynews.co.th (DevMan Ransomware)
https://www.gmanetwork.com/news/(DevMan Ransomware)
https://pestbusters.com.sg/
smvthailand.com
Chinese Healthcare Organisation (TBD)
Singapour Factory
South African IT firm (TBD)
South African Hr company (TBD)
dovesit.co.za (Ransomhub)
EU victim (To be discoled)
China Harbour (s) Engeneiring Company (Dragon Force Attack) FILE SAMPLE 1 avaliable /CHEC/
Premier Meats South Africa(Only files where exflitrated)
Feel Four (QILIN Attack)
Singapour Victim (To be discoled)
Honk Kong Victim (To be discoled)
China Harbour (s) Engeneiring Company (Dragon Force Attack)
FEELFOUR (QILIN)
Company located in catalonia ES (Name - soon)
Med institute (Name - soon)
Prvate hospital (Name - soon)
Bangkok Electronics Co., Ltd (QILIN)
Tawasol (APOS Attack) Screen
Texas Construction Firm(QILIN)
Optimax Technology(QILIN)
Doumen.fr(QILIN)
Dubai Company
Texas Construction Firm
Optimax Technology
doumen.fr
Note