Trending
ee-track">
Link copied!

Table of Contents

DevMan

Threat Actor Profile: DevMan 

Overview 

DevMan surfaced in March 2025 as a multi-affiliate ransomware operator, running attacks under the banner of several ransomware-as-a-service (RaaS) programs, including Lynx, DragonForce, Qilin, Apos, INC Ransom, RansomHub, and El Dorado (BlackLock). The group began as a DragonForce affiliate, but its malware builds gradually drifted away from that lineage in both structure and behavior. 

By early June 2025, DevMan claimed to be running its own, independently built encryptor, and it had already started publishing victims on a newly stood-up onion data leak site since April — a clear signal that the group was moving from affiliate work toward running its own ransomware operation. 

The encryptor DevMan deploys still carries the fingerprints of its DragonForce origins (itself a descendant of Conti), but it has picked up distinguishing traits of its own: a .devman file extension, custom mutex strings, and a ransom note that is sometimes encrypted along with the rest of the victim’s files.  

That last detail, paired with inconsistent behavior across operating systems — a wallpaper-change feature that only functions on Windows 10, for instance — points to an encryptor that is still being actively developed and tested rather than a finished, stable product. 

Technical Capability of the Encryptor 

DevMan’s ransomware supports a multi-mode encryption system, giving operators the choice between full encryption, a partial “header-only” mode, or a custom encryption scheme. To make recovery harder, it deletes Volume Shadow Copies, and it leans on the Windows Restart Manager to force open file locks so encryption can proceed cleanly. The malware also attempts lateral movement through SMB probing, though there is no evidence of self-replicating or worm-like propagation.

One notable flaw: the filename-mangling routine is deterministic but broken, to the point where even the ransom notes and decoy readme files it drops end up unreadable — a mistake rarely seen in tooling from more established ransomware operators.

Operational Pivot and Public Statements 

DevMan’s public statements track closely with its technical evolution. The group has said it abandoned DragonForce’s encryptor entirely, a claim consistent with the technical drift observed between April and June 2025. That timeline lines up with its shift away from shared RaaS infrastructure toward operating its own data leak site, payment portal, and — potentially — victim/customer support functions, all of which point to growing operational maturity. 

In July 2025, DevMan stated on X (formerly Twitter) that it had also stopped using Qilin’s ransomware, citing vulnerabilities in Qilin’s encryptor and poor financial returns from Qilin’s affiliate model. On 3 July 2025, the group announced via the same X account its intention to rewrite its ransomware codebase in Rust. 

DevMan has maintained an active presence on X since September 2023, where it posts samples tied to its attacks and engages in overt extortion by commenting directly on victim organizations’ corporate social media pages — behavior aimed both at pressuring victims into paying and at drawing attention from security researchers and the wider cybercrime community. 

The group’s original onion-based data leak site went offline on 7 June 2025. In early July, a more structured, updated version launched — referred to as the DevMan 2.0 DLS — confirming the group’s move into a full RaaS model. The new site includes a dedicated affiliate recruitment section, offering a 90/10 profit split for affiliates who bring their own initial access, or a 70/30 split for those who use DevMan’s own initial-access services. Its targeting rules are aggressive: any country outside the CIS is fair game, and critical infrastructure is explicitly not off-limits.  

Baseline targeting criteria call for organizations with revenue above USD 100 million (USD 50 million for healthcare targets), with negotiation possible for critical infrastructure victims. Affiliates only gain access to the full locker deployment panel after successfully completing an initial operation. 

DevMan has also claimed possession of a custom exploit for compromising Fortinet VPN appliances, and has referenced using Mimikatz to harvest credentials after gaining access to a victim environment. In April 2025, the group shared an image referencing a supposed new build labeled “DevMan 3.0,” styled visually to resemble the interface of Nova ransomware, a separate and established RaaS platform — though no onion service or sample accompanied the claim. 

Possible Identity and Law Enforcement Speculation 

DevMan has been linked to a now-banned XSS forum user going by brokeasf, who had previously sold corporate access and solicited information on lockers, encryptors, and partnerships with other ransomware groups. Separately, forum chatter has speculated about a possible law enforcement connection to DevMan, pointing to the alias Sozdatel, associated with the group’s Telegram account. 

An X-based doxxing account, @GangExposed, published an article claiming to have gathered thousands of messages attributed to DevMan and cross-referenced them against leaked Conti chat logs. Based on that comparison, @GangExposed identified DevMan, with high confidence, as an individual named Oleg Nefedov, alias “Tramp,” and linked him to a prior role as a Conti affiliate. The exposure damaged DevMan’s operational anonymity and reportedly weakened its standing among peers in the cybercrime community. 

May 2025 Ransomware Landscape Context 

Cyble previously covered DevMan’s rise in its Ransomware Landscape May 2025 reporting, alongside SafePay, which took the top spot among active ransomware groups that month. Ransomware groups collectively claimed 384 victims in May 2025 — the third consecutive monthly decline — amid a leadership reshuffle following RansomHub’s disappearance at the end of March, an outage possibly linked to an infrastructure compromise carried out by rival group DragonForce. 

DevMan claimed 13 victims in May 2025, placing it just behind the leading ransomware groups for the month and marking it as an operation to watch. In one attack on a media organization in Thailand, DevMan claimed to have encrypted all systems and NAS devices using its customized encryptor, applying a .devman1 file extension. The group stated the intrusion used an upgraded version of its malware capable of faster lateral movement, deployed via Group Policy Object (GPO). 

Screenshots published on DevMan’s leak site during this period appeared to show access to file shares, server management interfaces, domain controller settings, and encrypted directories. The group claimed to have exfiltrated 170 GB of data from the victim and expressed willingness to sell it to a single buyer. At the time, DevMan’s affiliations spanned Qilin, Apos, and DragonForce, with RansomHub added to its list of multi-RaaS relationships shortly after. 

Targeting Profile 

DevMan’s targeting footprint spans 117 countries, covering virtually every region outside the CIS bloc. Its victim base includes nations across the Middle East, Asia-Pacific, the Americas, Europe, and Africa, among them the UAE, Argentina, Australia, Bangladesh, Brazil, Canada, China, Germany, India, Indonesia, Israel, Japan, Pakistan, Saudi Arabia, South Africa, the United Kingdom, and the United States, alongside many others. 

This geographic reach is matched by an equally broad industry focus, with 27 sectors identified as targets. These range across critical and commercial verticals alike, including Aerospace & Defense, Agriculture & Livestock, Automotive, BFSI, Chemicals, Construction, Consumer Goods, Critical Infrastructure, Education, Energy & Utilities, Food & Beverages, Government & LEA, Healthcare, Hospitality, IT & ITES, Manufacturing, Media & Entertainment, Metals, Minerals & Mining, Pharmaceuticals & Biotechnology, Professional Services, Real Estate, Retail, Technology, Telecommunication, and Transportation & Logistics. 

DevMan’s operational network also extends through its affiliate relationships with other ransomware groups, having worked with or drawn on infrastructure tied to DragonForce, INC Ransom, Lynx, Qilin, and RansomHub. 

Associated Malware Families 

DevMan’s toolkit draws on a mix of ransomware payloads and supporting utilities tied to its various affiliate relationships. DragonForce, the ransomware family DevMan originally operated under as an affiliate, is itself a descendant of the leaked Conti codebase and forms the technical basis from which DevMan’s own encryptor diverged. Lynx, another ransomware strain DevMan has been linked to, is tracked more broadly as malware as well, reflecting its use beyond simple file encryption.  

RansomHub, one of the most prolific ransomware operations prior to its disappearance at the end of March 2025, represents a further affiliate program DevMan has claimed association with. The DEVMAN family itself refers to the group’s own custom-built encryptor, distinguished by its .devman file extension and the operational quirks noted throughout its development.  

INC Ransomware, tracked as a general malware family, ties back to DevMan’s affiliations with the INC Ransom group. Finally, Mimikatz — not a ransomware strain but a widely used credential-stealing and keylogging tool — has been directly observed in DevMan’s attacks, where it was used to harvest credentials from compromised environments to support lateral movement across victim networks. 

MITRE ATT&CK Techniques Mapped to DevMan 

  • Initial Access – Valid Accounts (T1078): Mimikatz has been used in at least one confirmed attack to harvest credentials for lateral movement, indicating reliance on stolen or dumped credentials to authenticate across internal systems post-compromise. 
  • Initial Access – External Remote Services (T1133): DevMan has claimed use of a custom exploit targeting Fortinet VPN appliances to gain an initial foothold. 
  • Execution – Windows Command Shell (T1059.003): Observed use of Mimikatz alongside locker deployment methods suggests reliance on command-line scripts and batch operations to automate tasks, manage privileges, and deploy ransomware payloads. 
  • Persistence – Valid Accounts (T1078): Harvested credentials are reused to maintain authenticated access across compromised systems. 
  • Persistence – External Remote Services (T1133): Claimed exploitation of Fortinet VPN appliances also supports persistent access into victim environments. 
  • Persistence – Registry Run Keys / Startup Folder (T1547.001): Not fully confirmed in captured samples, but consistent with typical persistence behavior inherited from DevMan’s DragonForce/Conti code lineage. 
  • Privilege Escalation – Valid Accounts (T1078): Credential harvesting via Mimikatz supports privilege escalation as well as lateral movement across a victim’s network. 
  • Privilege Escalation – Registry Run Keys / Startup Folder (T1547.001): Same reasoning as under Persistence — inherited behavior from prior code lineage that remains unconfirmed in samples. 
  • Defense Evasion – Obfuscated Files or Information (T1027): DevMan samples use string obfuscation and function encryption within the binary to evade detection and complicate reverse engineering, including customized mutex strings and ransom note encryption — sometimes to the point of the note itself becoming unreadable. 
  • Defense Evasion – Valid Accounts (T1078): Legitimate credential use, rather than malware deployment, helps blend DevMan’s activity in with normal account behavior. 

Conclusion 

DevMan has moved fast from multi-RaaS affiliate to independent operator — its own encryptor, leak site, affiliate program, and public extortion presence on X — even as its malware shows clear signs of active development, from OS-inconsistent features to a broken filename-mangling routine that scrambles its own ransom notes. Its 117-country, 27-industry targeting scope and claimed tools, including a Fortinet VPN exploit and Mimikatz-based credential theft, point to a group scaling quickly, while doxxing claims and unresolved law-enforcement speculation around the “Sozdatel” alias keep attribution murky. 

Organizations matching DevMan’s targeting profile — particularly those running Fortinet VPN infrastructure — should watch for credential misuse, Mimikatz activity, unusual SMB traffic, and unauthorized Volume Shadow Copy changes. 

Groups like DevMan move fast — Cyble Vision moves faster. Track leak sites, affiliate chatter, and emerging TTPs in real time before you become the next victim.  
 
Check out Cyble Vision today! 

Frequently Asked Questions (FAQs) 

What is DevMan? 

 DevMan is a ransomware group that emerged in March 2025, initially operating as a multi-RaaS affiliate for groups like DragonForce, Qilin, Lynx, INC Ransom, and RansomHub before transitioning to its own independent encryptor and data leak site by mid-2025. 

What does DevMan target? 

 DevMan targets organizations in 117 countries across every region outside the CIS bloc, with a baseline requirement of targeting companies with over USD 100 million in revenue, or USD 50 million for healthcare organizations. 

What industries are targeted? 

 27 sectors, including BFSI, Critical Infrastructure, Energy & Utilities, Government & LEA, Healthcare, IT & ITES, Manufacturing, Pharmaceuticals & Biotechnology, Technology, and Transportation & Logistics, among others. 

What ransomware or tools does DevMan use? 

 Its own custom DEVMAN encryptor (derived from DragonForce/Conti code), alongside claimed use of a Fortinet VPN exploit and Mimikatz for credential harvesting and lateral movement. 

Has DevMan’s identity been exposed? 

 An X-based doxxing account, @GangExposed, claimed with high confidence to have identified DevMan as an individual named Oleg Nefedov, alias “Tramp,” a former Conti affiliate — though this remains an unverified third-party claim. 

Is DevMan linked to law enforcement? 

 Forum speculation has raised the possibility of a law enforcement connection tied to the alias “Sozdatel,” DevMan’s Telegram handle, but this remains unconfirmed. 

What is DevMan’s primary attack method? 

 A combination of valid-account and credential abuse (via Mimikatz), exploitation of Fortinet VPN appliances, and deployment of its own multi-mode ransomware encryptor. 

Which MITRE ATT&CK techniques are associated with the group? 

 Valid Accounts (T1078), External Remote Services (T1133), Windows Command Shell (T1059.003), Registry Run Keys/Startup Folder (T1547.001), and Obfuscated Files or Information (T1027). 

What should organizations do to defend against DevMan? 

 Monitor for credential misuse and Mimikatz-style activity, patch and secure Fortinet VPN appliances, watch for unusual SMB traffic, and monitor for unauthorized changes to Volume Shadow Copy configurations. 

Media Disclaimer: This profile is based on the supplied threat-intelligence information and associated MITRE ATT&CK technique descriptions. It is intended for cybersecurity research, threat awareness, detection engineering, and defensive planning. Organizations should independently validate attribution, indicators, targeting information, and campaign details before using them for operational security decisions. 

Discover how we help proactively defend against evolving threats with Gen 3 intelligence. Request a Demo today!

Share Post:

Stay Informed

The Cyber Briefing Security Teams Actually Read!

Join security teams across 50+ countries getting Cyble's weekly research, advisories, and analyst insights.

No spam, ever. Unsubscribe anytime.

Related Topics

Scroll to Top

Book your session

Request a Personalized Demo

See how Cyble's threat intelligence protects your organization. A specialist will reach out within one business day.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams

Download the brochure

Get the Cyble Vision Brochure

Explore how Cyble Vision delivers AI-powered threat intelligence across your attack surface. Fill in your details to access the brochure.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams