Ransomware
DevManDevman's PlaceDevman 2.0Devman2
Attribution
Devman is the persona/handle of a single ransomware operator who emerged in 2025, initially as an affiliate of established RaaS operations (variously reported as Qilin, DragonForce, RansomHub and INC Ransom) before launching an independent brand and RaaS platform. The operator maintains a public presence on X/Twitter and engages directly with researchers, and has claimed prior embedded access within Conti's leadership (allegedly observing negotiations alongside 'Stern') — a self-reported claim that is unverified. In June 2025 a GangExposed doxing effort published alleged operator identity details; these have not been independently confirmed. Attribution to a nation-state is not asserted; this is a financially motivated cybercriminal.
Motivation
Financial (double-extortion ransomware / Ransomware-as-a-Service)
Attribution confidence
medium
Sectors
Government/defense, professional services
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it mattersRansomware actor, medium confidence, documented targeting Egypt, UAE (Government/defense, professional services sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.