Devman is the persona/handle of a single ransomware operator who emerged in 2025, initially as an affiliate of established RaaS operations (variously reported as Qilin, DragonForce, RansomHub and INC Ransom) before launching an independent brand and RaaS platform. The operator maintains a public presence on X/Twitter and engages directly with researchers, and has claimed prior embedded access within Conti's leadership (allegedly observing negotiations alongside 'Stern') — a self-reported claim that is unverified. In June 2025 a GangExposed doxing effort published alleged operator identity details; these have not been independently confirmed. Attribution to a nation-state is not asserted; this is a financially motivated cybercriminal.
Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
ANY.RUN: sample writes Restart Manager session metadata under HKCU\Software\Microsoft\RestartManager\Session0000 then deletes the entries to limit forensic traces; ANY.RUN and Halcyon map T1070.
Halcyon and Vectra report RDP used for lateral movement alongside SMB (T1021.001).
Regional co-occurrence · associated techniques
Honesty note
Regional co-occurrence is association, not prediction. These techniques appeared alongside Devman's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 7 techniques
Advanced Anti-Phishing T1566partialApp GovernanceT1562significantAnti-SpoofingT1566significantDefender for Cloud AppsT1133partialDefender for Cloud AppsT1567partialDefender for Cloud AppsT1567.002partialConditional AccessT1078minimalIdentity Secure ScoreT1078minimalMultifactor AuthenticationT1078minimalMultifactor AuthenticationT1566partialPrivileged Identity ManagementT1078minimalPassword PolicyT1078significantPassword ProtectionT1078partialRole Based Access ControlT1078minimalRole Based Access ControlT1562minimalAntimalwareT1566significantAnti-PhishingT1566significantAntiSpamT1566significantAudit SolutionsT1078partialAudit SolutionsT1562partialInformation ProtectionT1070significantInformation ProtectionT1567significant
detect · 12 techniques
Advanced Anti-Phishing T1566partialApp GovernanceT1078significantApp GovernanceT1562significantApp GovernanceT1566significantAdvanced Threat HuntingT1078significantAdvanced Threat HuntingT1562significantAdvanced Threat HuntingT1566significantAdvanced Threat HuntingT1567significantDefender for Cloud AppsT1078partialDefender for Cloud AppsT1133partialDefender for Cloud AppsT1486partialDefender for Cloud AppsT1567partialDefender for Cloud AppsT1567.002partialMicrosoft Defender for Identity
respond · 4 techniques
Advanced Anti-Phishing T1566partialAutomated Investigation and ResponseT1078significantAutomated Investigation and ResponseT1566significantAutomated Investigation and ResponseT1567significantIncident ResponseT1078minimalIncident ResponseT1562minimalIncident ResponseT1566minimalQuarantine PoliciesT1566significantSafe AttachmentsT1566significantATT&CK Simulation TrainingT1566partialZero Hour Auto PurgeT1566significantConditional AccessT1078minimal
Countermeasures · D3FEND
Defensive techniques that counter Devman's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.