Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Devman is a financially motivated ransomware brand that emerged in April 2025, initially operating as an affiliate of multiple RaaS programs and then spinning up its own locker and leak infrastructure. Its encryptor is a customized derivative of DragonForce code, which itself traces to the leaked Conti source code (February 2022). Devman ran early leak sites 'Devman's Place' and 'Devman 2.0' before consolidating onto a dedicated RaaS portal (launched circa September 30, 2025) offering Windows, Linux, NAS and ESXi variants, a claimed SCADA/ICS locker, affiliate recruitment with a deposit requirement, and revenue-share commissions. Ransomware.live lists roughly 184 claimed victims across ~39 countries, spanning technology, healthcare and financial-services sectors. No new victims have been posted since February 4, 2026 and the operation appears dormant, though the operator is assessed (moderate confidence by outside reporting) to remain active.
Devman first appeared in mid-April 2025 as a ransomware affiliate working across several RaaS operations, and by July 2025 had transitioned to independent operations using modified DragonForce code, opening the 'Devman's Place' and 'Devman 2.0' leak sites. A dedicated RaaS portal launched around September 30, 2025, centralizing payload builds, victim management and affiliate payouts. Technical analysis (ANY.RUN, July 2025) confirmed extensive code overlap with DragonForce, including identical ransom-note formatting and Windows Restart Manager abuse. Multiple vendors (Vectra, Cyble, Analyst1, Halcyon) place Devman in the Conti -> Black Basta/DragonForce rebrand lineage. A June 2025 GangExposed doxing exposed alleged operator identities. Activity ceased after February 4, 2026 (no new leak-site posts), with the RaaS shutdown reason unexplained. MENA relevance: REAL. Devman's leak site includes concrete, named MENA victims corroborated across ransomware.live and vendor reporting — Egypt: EEHC (eehc.gov.eg, Egyptian Electricity Holding Company, a government entity, ~$2.27M demand); UAE: a Dubai-based company (reported using a different encryption method). Additional MENA victims outside the current country tags include Tunisia (Hopital La Rabta), Lebanon (Solidere) and Jordan (Abdulhadi Hospital). The current RaqibCTI Egypt and UAE tags are therefore backed by real, named leak-site listings rather than thin or speculative claims; note that leak-site listings are self-reported by the actor and were not independently victim-confirmed. Consider adding Tunisia, Lebanon and Jordan tags for completeness.
+16 more relationships — see the relationships browser.