Devman Ransomware
TrackedThreat actor group tracked in the global ransomware database · Last disclosure: Feb 4, 2026
ThreatAI Analysis
Compiled from the ransomware.live profile for Devman and from this database. Figures and technique mappings are quoted from the source data, not inferred.
Devman is a ransomware threat actor responsible for infecting 184 victims across 39 countries, with the United States hardest hit by this group's activities.
Who Devman is
Former RansomHub and INC Ransom affiliate.
Recorded activity
Disclosures attributed to Devman in this database run from April 2025 to February 2026, totalling 184 victims — 0.9% of everything tracked here. Devman has listed victims in 39 countries in this database, most often United States, followed by France and Taiwan. The sectors appearing most in its listings are Healthcare, Technology, Financial Services.
How Devman is documented to operate
Valid Accounts T1078 Stealth Persistence
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network.
Mitigations: Application Developer Guidance, User Training, Password Policies, User Account Management, Privileged Account Management, Multi-factor Authentication
MITRE ATT&CK reference →Exploitation of Remote Services T1210 Lateral Movement
Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. A common goal for post-compromise exploitation of remote services is for lateral movement to enable access to a remote system.
Mitigations: Vulnerability Scanning, Network Segmentation, Threat Intelligence Program, Privileged Account Management, Application Isolation and Sandboxing, Exploit Protection
MITRE ATT&CK reference →PowerShell T1059.001 Execution
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <codeStart-Process</code cmdlet which can be used to run an executable and the <codeInvoke-Command</code cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).
Mitigations: Execution Prevention, Code Signing, Privileged Account Management, Antivirus/Antimalware, Disable or Remove Feature or Program
MITRE ATT&CK reference →Exploitation for Client Execution T1203 Execution
Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system.
Mitigations: Application Isolation and Sandboxing, Exploit Protection, Update Software
MITRE ATT&CK reference →Exploitation for Privilege Escalation T1068 Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Mitigations: Execution Prevention, Threat Intelligence Program, Application Isolation and Sandboxing, Exploit Protection, Update Software
MITRE ATT&CK reference →Masquerading T1036 Stealth
Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names. Renaming abusable system utilities to evade security monitoring is also a form of Masquerading.
Mitigations: User Training, Execution Prevention, Code Signing, Behavior Prevention on Endpoint, User Account Management, Restrict File and Directory Permissions
MITRE ATT&CK reference →Disable or Modify Tools T1685 Defense Impairment
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Mitigations: Execution Prevention, User Account Management, Restrict File and Directory Permissions, Restrict Registry Permissions, Software Configuration, Audit
MITRE ATT&CK reference →OS Credential Dumping T1003 Credential Access
Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures. Credentials can then be used to perform Lateral Movement and access restricted information. Several of the tools mentioned in associated sub-techniques may be used by both adversaries and professional security testers. Additional custom tools likely exist as well.
Mitigations: Encrypt Sensitive Information, Behavior Prevention on Endpoint, Password Policies, User Training, Privileged Account Management, Privileged Process Integrity
MITRE ATT&CK reference →Remote System Discovery T1018 Discovery
Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality could exist within remote access tools to enable this, but utilities available on the operating system could also be used such as Ping, <codenet view</code using Net, or, on ESXi servers, esxcli network diag ping. Adversaries may also analyze data from local host files (ex: <codeC:\Windows\System32\Drivers\etc\hosts</code or <code/etc/hosts</code) or other passive means (such as local Arp cache entries) in order to discover the presence of remote systems in an environment.
MITRE ATT&CK reference →MITRE ATT&CK techniques attributed to Devman across its recorded activity. They describe the group overall, not any single incident.
Indicators of compromise
- 83.217.209.210
- 38.132.122.213
- 38.132.122.214
Showing a sample of 3 IP on file. Hashes and network indicators published for Devman. Leak-site addresses are deliberately excluded. Indicators age quickly — treat a match as a starting point for investigation, and an absence of matches as no assurance.
YARA detection rules
devman.yar
/*
devman ransomware
*/
rule devman_Ransomnote
{
meta:
author = "ransomware.live"
family = "ransomware.devman"
description = "Detects devman ransomware ransom note or artifact"
date = "2026-05-04"
severity = 7
score = 70
strings:
$name1 = "devman" ascii nocase
$name2 = "DEVMAN" ascii
$onion = "devman.onion" ascii nocase
condition:
any of them
}
Community-contributed rules for Devman, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.
Threat Actor Analysis
Devman is a ransomware threat group that has disclosed 184 victims in publicly accessible leak site data, representing 0.9% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Devman in our dataset dates to April 2025.
Geographically, Devman has targeted organisations in 39 countries. The most frequently targeted nation is United States with 44 victim organisations. Other heavily targeted nations include France, Taiwan, SJ.
Industry-wise, Devman shows a concentration in the Healthcare, Technology, Financial Services sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime — conditions that increase ransom payment likelihood.
Like most modern ransomware operations, Devman likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.
Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 100 most recent of the 184 disclosures we hold for this group; use the link beneath it to page through all of them.
Recent Victim Disclosures (showing 100 of 184)
| # | Organization | Country | Sector | Date |
|---|---|---|---|---|
| 1 | Crystal Coast Pain Management crystalcoastpm.com | 🇺🇸 United States | Healthcare | Feb 4, 2026 |
| 2 | ENCOMPASS-INC encompass-inc.com | 🇺🇸 United States | Financial Services | Feb 2, 2026 |
| 3 | wjnklaw.com wjnklaw.com | 🇺🇸 United States | — | Jan 30, 2026 |
| 4 | woodwardoralsurgery.com woodwardoralsurgery.com | SJ | Healthcare | Jan 30, 2026 |
| 5 | consultaegis.com consultaegis.com | 🇺🇸 United States | Public Sector | Jan 29, 2026 |
| 6 | zallc.org zallc.org | 🇺🇸 United States | Financial Services | Jan 29, 2026 |
| 7 | **ps.net **ps.net | 🇺🇸 United States | — | Jan 28, 2026 |
| 8 | tiw-group.com tiw-group.com | SJ | Technology | Jan 28, 2026 |
| 9 | ***vandenberg.com ***vandenberg.com | 🇺🇸 United States | — | Jan 28, 2026 |
| 10 | z*l*c.o*g z*l*c.o*g | 🇺🇸 United States | Financial Services | Jan 28, 2026 |
| 11 | twi-group.com twi-group.com | 🇺🇸 United States | Transportation/Logistics | Jan 27, 2026 |
| 12 | c*n**lta**i*.com c*n**lta**i*.com | 🇺🇸 United States | Public Sector | Jan 26, 2026 |
| 13 | cs.at cs.at | 🇦🇹 Austria | Financial Services | Jan 26, 2026 |
| 14 | **.at **.at | 🇦🇹 Austria | — | Jan 25, 2026 |
| 15 | ****cr*nem*ds.c*m ****cr*nem*ds.c*m | SJ | Healthcare | Jan 24, 2026 |
| 16 | ***-gr*up.com | SJ | — | Jan 24, 2026 |
| 17 | automax.com automax.com | 🇮🇳 India | Consumer Services | Jan 21, 2026 |
| 18 | ***m*sic.fi ***m*sic.fi | 🇫🇮 Finland | — | Jan 21, 2026 |
| 19 | ***om****s-***.com ***om****s-***.com | 🇺🇸 United States | — | Jan 21, 2026 |
| 20 | Syrmasgs syrmasgs.com | 🇮🇳 India | Business Services | Jan 21, 2026 |
| 21 | www.****law.com | 🇺🇸 United States | Financial Services | Jan 21, 2026 |
| 22 | www.mims.com www.mims.com | SN | Healthcare | Jan 21, 2026 |
| 23 | www.saundersandsaunders.com www.saundersandsaunders.com | 🇺🇸 United States | — | Jan 21, 2026 |
| 24 | Tvgoiania tvgoiania.com.br | 🇧🇷 Brazil | Consumer Services | Jan 20, 2026 |
| 25 | consigaz.com.br consigaz.com.br | 🇧🇷 Brazil | Energy | Jan 12, 2026 |
| 26 | klhindustries.com klhindustries.com | 🇺🇸 United States | Manufacturing | Jan 12, 2026 |
| 27 | ******m*di*al.com ******medical.com | 🇺🇸 United States | Healthcare | Jan 12, 2026 |
| 28 | pronaca.com pronaca.com | SJ | Agriculture and Food Production | Jan 12, 2026 |
| 29 | s***p.com s***p.com | SJ | Business Services | Jan 12, 2026 |
| 30 | sealbeachca.gov sealbeachca.gov | 🇺🇸 United States | Public Sector | Jan 12, 2026 |
| 31 | sealbeachpd.com sealbeachpd.com | 🇺🇸 United States | Public Sector | Jan 12, 2026 |
| 32 | ****t*lc*a*tpm.com ****t*lc*a*tpm.com | SJ | Healthcare | Jan 12, 2026 |
| 33 | Intonu.com Intonu.com | 🇺🇸 United States | Financial Services | Dec 28, 2025 |
| 34 | Jennings SD Jennings SD | 🇺🇸 United States | Financial Services | Dec 28, 2025 |
| 35 | oppor**nity*****.org oppor**nity*****.org | 🇺🇸 United States | Healthcare | Dec 28, 2025 |
| 36 | sharinc.org sharinc.org | 🇺🇸 United States | Business Services | Dec 28, 2025 |
| 37 | i**o**.us i**o**.us | 🇺🇸 United States | Technology | Dec 25, 2025 |
| 38 | ***ind***es.com ***ind***es.com | 🇺🇸 United States | Business Services | Dec 25, 2025 |
| 39 | kavi.fi kavi.fi | 🇫🇮 Finland | Business Services | Dec 25, 2025 |
| 40 | British Holiday & Home Parks Association Ltd www.bhhpa.org.uk | 🇬🇧 United Kingdom | Hospitality and Tourism | Dec 22, 2025 |
| 41 | Clínica Dávila davila.cl | 🇨🇱 Chile | Healthcare | Dec 22, 2025 |
| 42 | k*v*.fi k*v*.fi | 🇫🇮 Finland | Business Services | Dec 22, 2025 |
| 43 | transrocamar.com transrocamar.com | 🇪🇸 Spain | Financial Services | Dec 22, 2025 |
| 44 | consult*****.c** consult*****.c** | 🇺🇸 United States | Financial Services | Dec 19, 2025 |
| 45 | Culinary Jet Concierge www.culinaryjetconcierge.com | 🇫🇷 France | Hospitality and Tourism | Dec 19, 2025 |
| 46 | *n**e-ai *n**e-ai.com | 🇨🇳 China | Technology | Dec 19, 2025 |
| 47 | ****s*oc****.com ****s*oc****.com | 🇪🇸 Spain | Financial Services | Dec 19, 2025 |
| 48 | beausejourco-op.crs beausejourco-op.crs | 🇨🇦 Canada | Agriculture and Food Production | Dec 18, 2025 |
| 49 | d*v***.cl d*v***.cl | 🇨🇱 Chile | Healthcare | Dec 18, 2025 |
| 50 | Axion50plus www.axion50plus.org | 🇨🇦 Canada | Financial Services | Dec 17, 2025 |
| 51 | Jet ******** Jet ******** | 🇫🇷 France | Transportation/Logistics | Dec 17, 2025 |
| 52 | a**o*50*****.org a**o*50*****.org | 🇨🇦 Canada | Financial Services | Dec 16, 2025 |
| 53 | b**u**jou***-**.crs b**u**jou***-**.crs | 🇨🇦 Canada | Financial Services | Dec 16, 2025 |
| 54 | Productos Lácteos Flor de Aragua CA www.unre.com | — | Agriculture and Food Production | Dec 16, 2025 |
| 55 | DXS SYSTEMS dxs-systems.co.uk | 🇬🇧 United Kingdom | Technology | Dec 15, 2025 |
| 56 | CANCER cancer.org.br | 🇧🇷 Brazil | Financial Services | Dec 14, 2025 |
| 57 | ***-***tems.*** ***-***tems.*** | 🇬🇧 United Kingdom | — | Dec 14, 2025 |
| 58 | Hopital La Rabta www.chularabta.tn | TN | Healthcare | Dec 12, 2025 |
| 59 | Quezon Power www.qpl.com.ph | 🇵🇭 Philippines | Energy | Dec 12, 2025 |
| 60 | C*NC*R c*nc*r.o*g.** | 🇧🇷 Brazil | Financial Services | Dec 11, 2025 |
| 61 | Hopital ** ***** *h*l*r*b*a.tn | TN | Healthcare | Dec 11, 2025 |
| 62 | www.digital****.com www.digital****.com | 🇺🇸 United States | Technology | Dec 11, 2025 |
| 63 | fassic.org fassic.org | 🇫🇷 France | Healthcare | Dec 9, 2025 |
| 64 | Inter care theintracare.com | 🇺🇸 United States | Healthcare | Dec 9, 2025 |
| 65 | Village Santé Saint Joseph Hospital fassic.org | 🇫🇷 France | Healthcare | Dec 9, 2025 |
| 66 | arko.no arko.no | 🇳🇴 Norway | — | Dec 7, 2025 |
| 67 | f***i*.o*g f***i*.o*g | 🇫🇷 France | Financial Services | Dec 7, 2025 |
| 68 | hopital-*********.com | 🇫🇷 France | Healthcare | Dec 7, 2025 |
| 69 | S**** Saint ****** S**** Saint ****** | 🇫🇷 France | Healthcare | Dec 7, 2025 |
| 70 | solidere solidere | LB | Construction | Dec 7, 2025 |
| 71 | cpasch.com cpasch.com | 🇺🇸 United States | Business Services | Dec 3, 2025 |
| 72 | n*w*****.com | — | — | Dec 2, 2025 |
| 73 | ravand.com ravand.com | 🇨🇦 Canada | Technology | Dec 2, 2025 |
| 74 | a*f*o.us | — | — | Dec 1, 2025 |
| 75 | Abdulhadi Hospital ecaretest.com | 🇯🇴 Jordan | Healthcare | Dec 1, 2025 |
| 76 | c*a*c*.c*m | — | Technology | Dec 1, 2025 |
| 77 | m*tt**ca**r**.**.it | — | — | Dec 1, 2025 |
| 78 | newhorizonsmedical.org newhorizonsmedical.org | 🇺🇸 United States | Healthcare | Dec 1, 2025 |
| 79 | www.eastersealsnei.org www.eastersealsnei.org | 🇺🇸 United States | Consumer Services | Dec 1, 2025 |
| 80 | gsccca.org gsccca.org | 🇺🇸 United States | Public Sector | Nov 21, 2025 |
| 81 | procure.com procure.com | 🇺🇸 United States | Business Services | Nov 21, 2025 |
| 82 | future.com.bo future.com.bo | BO | — | Nov 19, 2025 |
| 83 | MCC mcchemical.com | 🇺🇸 United States | Manufacturing | Nov 19, 2025 |
| 84 | ****clinic.com.** | — | Healthcare | Nov 17, 2025 |
| 85 | f*t*r*.com.** | — | — | Nov 17, 2025 |
| 86 | ctfc.cat ctfc.cat | 🇪🇸 Spain | — | Nov 12, 2025 |
| 87 | omniumint omniumint.com | 🇺🇸 United States | — | Nov 11, 2025 |
| 88 | www.oucru.org www.oucru.org | 🇻🇳 Vietnam | Education | Nov 5, 2025 |
| 89 | www.heitech.com.my www.heitech.com.my | 🇲🇾 Malaysia | Technology | Nov 4, 2025 |
| 90 | juntalocal.cdmx.gob.mx juntalocal.cdmx.gob.mx | 🇲🇽 Mexico | Public Sector | Nov 1, 2025 |
| 91 | m*c*e*ic*l.com | — | Healthcare | Nov 1, 2025 |
| 92 | o*c*u.o** | — | Technology | Nov 1, 2025 |
| 93 | fhw.org fhw.org | 🇺🇸 United States | Healthcare | Oct 28, 2025 |
| 94 | g*e*g*o**l.com | — | Technology | Oct 28, 2025 |
| 95 | h*i**c*.c*m.my | — | — | Oct 28, 2025 |
| 96 | h*tel*ys*e*s.pl | — | Hospitality and Tourism | Oct 28, 2025 |
| 97 | r*p**fl*wa*ps.com | — | Technology | Oct 28, 2025 |
| 98 | pharmaciedesalize.com.fr pharmaciedesalizes.fr | 🇫🇷 France | Healthcare | Oct 17, 2025 |
| 99 | www.o****m*nt.com | — | — | Oct 16, 2025 |
| 100 | EMBASY OF BOLIVIA DC boliviawdc.org | BO | Public Sector | Oct 15, 2025 |
Frequently Asked Questions
What is Devman ransomware?
Devman is a ransomware threat group that has claimed 184 victims since its first known activity in April 2025. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.
How many victims has Devman attacked?
Devman has claimed 184 victims in our database, representing 0.9% of all tracked ransomware attacks. The most targeted countries are United States, France, Taiwan, SJ.
Which countries does Devman target?
Devman has attacked organizations in 39 countries. The top targeted countries are: United States, France, Taiwan, SJ.
Which industries does Devman target?
Devman most frequently targets the Healthcare, Technology, Financial Services sectors based on victim disclosures in our database.
Is Devman still active?
Devman's most recent victim disclosure in our database was on February 4, 2026. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.