DE

Devman Ransomware

Tracked

Threat actor group tracked in the global ransomware database · Last disclosure: Feb 4, 2026

Ransomware-as-a-Service (RaaS) Double Extortion Target: Healthcare
184
Total Victims
0.9% of all tracked
39
Countries Targeted
14
Sectors Targeted
2025
First Seen

ThreatAI Analysis

Compiled from the ransomware.live profile for Devman and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Devman is a ransomware threat actor responsible for infecting 184 victims across 39 countries, with the United States hardest hit by this group's activities.

Who Devman is

Former RansomHub and INC Ransom affiliate.

Recorded activity

Disclosures attributed to Devman in this database run from April 2025 to February 2026, totalling 184 victims — 0.9% of everything tracked here. Devman has listed victims in 39 countries in this database, most often United States, followed by France and Taiwan. The sectors appearing most in its listings are Healthcare, Technology, Financial Services.

How Devman is documented to operate

Valid Accounts T1078 Stealth Persistence

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network.

Mitigations: Application Developer Guidance, User Training, Password Policies, User Account Management, Privileged Account Management, Multi-factor Authentication

MITRE ATT&CK reference →
Exploitation of Remote Services T1210 Lateral Movement

Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. A common goal for post-compromise exploitation of remote services is for lateral movement to enable access to a remote system.

Mitigations: Vulnerability Scanning, Network Segmentation, Threat Intelligence Program, Privileged Account Management, Application Isolation and Sandboxing, Exploit Protection

MITRE ATT&CK reference →
PowerShell T1059.001 Execution

Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <codeStart-Process</code cmdlet which can be used to run an executable and the <codeInvoke-Command</code cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).

Mitigations: Execution Prevention, Code Signing, Privileged Account Management, Antivirus/Antimalware, Disable or Remove Feature or Program

MITRE ATT&CK reference →
Exploitation for Client Execution T1203 Execution

Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system.

Mitigations: Application Isolation and Sandboxing, Exploit Protection, Update Software

MITRE ATT&CK reference →
Exploitation for Privilege Escalation T1068 Privilege Escalation

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Mitigations: Execution Prevention, Threat Intelligence Program, Application Isolation and Sandboxing, Exploit Protection, Update Software

MITRE ATT&CK reference →
Masquerading T1036 Stealth

Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names. Renaming abusable system utilities to evade security monitoring is also a form of Masquerading.

Mitigations: User Training, Execution Prevention, Code Signing, Behavior Prevention on Endpoint, User Account Management, Restrict File and Directory Permissions

MITRE ATT&CK reference →
Disable or Modify Tools T1685 Defense Impairment

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

Mitigations: Execution Prevention, User Account Management, Restrict File and Directory Permissions, Restrict Registry Permissions, Software Configuration, Audit

MITRE ATT&CK reference →
OS Credential Dumping T1003 Credential Access

Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures. Credentials can then be used to perform Lateral Movement and access restricted information. Several of the tools mentioned in associated sub-techniques may be used by both adversaries and professional security testers. Additional custom tools likely exist as well.

Mitigations: Encrypt Sensitive Information, Behavior Prevention on Endpoint, Password Policies, User Training, Privileged Account Management, Privileged Process Integrity

MITRE ATT&CK reference →
Remote System Discovery T1018 Discovery

Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality could exist within remote access tools to enable this, but utilities available on the operating system could also be used such as Ping, <codenet view</code using Net, or, on ESXi servers, esxcli network diag ping. Adversaries may also analyze data from local host files (ex: <codeC:\Windows\System32\Drivers\etc\hosts</code or <code/etc/hosts</code) or other passive means (such as local Arp cache entries) in order to discover the presence of remote systems in an environment.

MITRE ATT&CK reference →

MITRE ATT&CK techniques attributed to Devman across its recorded activity. They describe the group overall, not any single incident.

Indicators of compromise

  • 83.217.209.210
  • 38.132.122.213
  • 38.132.122.214

Showing a sample of 3 IP on file. Hashes and network indicators published for Devman. Leak-site addresses are deliberately excluded. Indicators age quickly — treat a match as a starting point for investigation, and an absence of matches as no assurance.

YARA detection rules

devman.yar
/*
devman ransomware
*/

rule devman_Ransomnote
{
    meta:
        author = "ransomware.live"
        family = "ransomware.devman"
        description = "Detects devman ransomware ransom note or artifact"
        date = "2026-05-04"
        severity = 7
        score = 70

    strings:
        $name1 = "devman" ascii nocase
        $name2 = "DEVMAN" ascii
        $onion  = "devman.onion" ascii nocase

    condition:
        any of them
}

Community-contributed rules for Devman, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.

Threat Actor Analysis

Devman is a ransomware threat group that has disclosed 184 victims in publicly accessible leak site data, representing 0.9% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Devman in our dataset dates to April 2025.

Geographically, Devman has targeted organisations in 39 countries. The most frequently targeted nation is United States with 44 victim organisations. Other heavily targeted nations include France, Taiwan, SJ.

Industry-wise, Devman shows a concentration in the Healthcare, Technology, Financial Services sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime — conditions that increase ransom payment likelihood.

Like most modern ransomware operations, Devman likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.

Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 100 most recent of the 184 disclosures we hold for this group; use the link beneath it to page through all of them.

Recent Victim Disclosures (showing 100 of 184)

# Organization Country Sector Date
1 Crystal Coast Pain Management crystalcoastpm.com 🇺🇸 United States Healthcare Feb 4, 2026
2 ENCOMPASS-INC encompass-inc.com 🇺🇸 United States Financial Services Feb 2, 2026
3 wjnklaw.com wjnklaw.com 🇺🇸 United States Jan 30, 2026
4 woodwardoralsurgery.com woodwardoralsurgery.com SJ Healthcare Jan 30, 2026
5 consultaegis.com consultaegis.com 🇺🇸 United States Public Sector Jan 29, 2026
6 zallc.org zallc.org 🇺🇸 United States Financial Services Jan 29, 2026
7 **ps.net **ps.net 🇺🇸 United States Jan 28, 2026
8 tiw-group.com tiw-group.com SJ Technology Jan 28, 2026
9 ***vandenberg.com ***vandenberg.com 🇺🇸 United States Jan 28, 2026
10 z*l*c.o*g z*l*c.o*g 🇺🇸 United States Financial Services Jan 28, 2026
11 twi-group.com twi-group.com 🇺🇸 United States Transportation/Logistics Jan 27, 2026
12 c*n**lta**i*.com c*n**lta**i*.com 🇺🇸 United States Public Sector Jan 26, 2026
13 cs.at cs.at 🇦🇹 Austria Financial Services Jan 26, 2026
14 **.at **.at 🇦🇹 Austria Jan 25, 2026
15 ****cr*nem*ds.c*m ****cr*nem*ds.c*m SJ Healthcare Jan 24, 2026
16 ***-gr*up.com SJ Jan 24, 2026
17 automax.com automax.com 🇮🇳 India Consumer Services Jan 21, 2026
18 ***m*sic.fi ***m*sic.fi 🇫🇮 Finland Jan 21, 2026
19 ***om****s-***.com ***om****s-***.com 🇺🇸 United States Jan 21, 2026
20 Syrmasgs syrmasgs.com 🇮🇳 India Business Services Jan 21, 2026
21 www.****law.com 🇺🇸 United States Financial Services Jan 21, 2026
22 www.mims.com www.mims.com SN Healthcare Jan 21, 2026
23 www.saundersandsaunders.com www.saundersandsaunders.com 🇺🇸 United States Jan 21, 2026
24 Tvgoiania tvgoiania.com.br 🇧🇷 Brazil Consumer Services Jan 20, 2026
25 consigaz.com.br consigaz.com.br 🇧🇷 Brazil Energy Jan 12, 2026
26 klhindustries.com klhindustries.com 🇺🇸 United States Manufacturing Jan 12, 2026
27 ******m*di*al.com ******medical.com 🇺🇸 United States Healthcare Jan 12, 2026
28 pronaca.com pronaca.com SJ Agriculture and Food Production Jan 12, 2026
29 s***p.com s***p.com SJ Business Services Jan 12, 2026
30 sealbeachca.gov sealbeachca.gov 🇺🇸 United States Public Sector Jan 12, 2026
31 sealbeachpd.com sealbeachpd.com 🇺🇸 United States Public Sector Jan 12, 2026
32 ****t*lc*a*tpm.com ****t*lc*a*tpm.com SJ Healthcare Jan 12, 2026
33 Intonu.com Intonu.com 🇺🇸 United States Financial Services Dec 28, 2025
34 Jennings SD Jennings SD 🇺🇸 United States Financial Services Dec 28, 2025
35 oppor**nity*****.org oppor**nity*****.org 🇺🇸 United States Healthcare Dec 28, 2025
36 sharinc.org sharinc.org 🇺🇸 United States Business Services Dec 28, 2025
37 i**o**.us i**o**.us 🇺🇸 United States Technology Dec 25, 2025
38 ***ind***es.com ***ind***es.com 🇺🇸 United States Business Services Dec 25, 2025
39 kavi.fi kavi.fi 🇫🇮 Finland Business Services Dec 25, 2025
40 British Holiday & Home Parks Association Ltd www.bhhpa.org.uk 🇬🇧 United Kingdom Hospitality and Tourism Dec 22, 2025
41 Clínica Dávila davila.cl 🇨🇱 Chile Healthcare Dec 22, 2025
42 k*v*.fi k*v*.fi 🇫🇮 Finland Business Services Dec 22, 2025
43 transrocamar.com transrocamar.com 🇪🇸 Spain Financial Services Dec 22, 2025
44 consult*****.c** consult*****.c** 🇺🇸 United States Financial Services Dec 19, 2025
45 Culinary Jet Concierge www.culinaryjetconcierge.com 🇫🇷 France Hospitality and Tourism Dec 19, 2025
46 *n**e-ai *n**e-ai.com 🇨🇳 China Technology Dec 19, 2025
47 ****s*oc****.com ****s*oc****.com 🇪🇸 Spain Financial Services Dec 19, 2025
48 beausejourco-op.crs beausejourco-op.crs 🇨🇦 Canada Agriculture and Food Production Dec 18, 2025
49 d*v***.cl d*v***.cl 🇨🇱 Chile Healthcare Dec 18, 2025
50 Axion50plus www.axion50plus.org 🇨🇦 Canada Financial Services Dec 17, 2025
51 Jet ******** Jet ******** 🇫🇷 France Transportation/Logistics Dec 17, 2025
52 a**o*50*****.org a**o*50*****.org 🇨🇦 Canada Financial Services Dec 16, 2025
53 b**u**jou***-**.crs b**u**jou***-**.crs 🇨🇦 Canada Financial Services Dec 16, 2025
54 Productos Lácteos Flor de Aragua CA www.unre.com Agriculture and Food Production Dec 16, 2025
55 DXS SYSTEMS dxs-systems.co.uk 🇬🇧 United Kingdom Technology Dec 15, 2025
56 CANCER cancer.org.br 🇧🇷 Brazil Financial Services Dec 14, 2025
57 ***-***tems.*** ***-***tems.*** 🇬🇧 United Kingdom Dec 14, 2025
58 Hopital La Rabta www.chularabta.tn TN Healthcare Dec 12, 2025
59 Quezon Power www.qpl.com.ph 🇵🇭 Philippines Energy Dec 12, 2025
60 C*NC*R c*nc*r.o*g.** 🇧🇷 Brazil Financial Services Dec 11, 2025
61 Hopital ** ***** *h*l*r*b*a.tn TN Healthcare Dec 11, 2025
62 www.digital****.com www.digital****.com 🇺🇸 United States Technology Dec 11, 2025
63 fassic.org fassic.org 🇫🇷 France Healthcare Dec 9, 2025
64 Inter care theintracare.com 🇺🇸 United States Healthcare Dec 9, 2025
65 Village Santé Saint Joseph Hospital fassic.org 🇫🇷 France Healthcare Dec 9, 2025
66 arko.no arko.no 🇳🇴 Norway Dec 7, 2025
67 f***i*.o*g f***i*.o*g 🇫🇷 France Financial Services Dec 7, 2025
68 hopital-*********.com 🇫🇷 France Healthcare Dec 7, 2025
69 S**** Saint ****** S**** Saint ****** 🇫🇷 France Healthcare Dec 7, 2025
70 solidere solidere LB Construction Dec 7, 2025
71 cpasch.com cpasch.com 🇺🇸 United States Business Services Dec 3, 2025
72 n*w*****.com Dec 2, 2025
73 ravand.com ravand.com 🇨🇦 Canada Technology Dec 2, 2025
74 a*f*o.us Dec 1, 2025
75 Abdulhadi Hospital ecaretest.com 🇯🇴 Jordan Healthcare Dec 1, 2025
76 c*a*c*.c*m Technology Dec 1, 2025
77 m*tt**ca**r**.**.it Dec 1, 2025
78 newhorizonsmedical.org newhorizonsmedical.org 🇺🇸 United States Healthcare Dec 1, 2025
79 www.eastersealsnei.org www.eastersealsnei.org 🇺🇸 United States Consumer Services Dec 1, 2025
80 gsccca.org gsccca.org 🇺🇸 United States Public Sector Nov 21, 2025
81 procure.com procure.com 🇺🇸 United States Business Services Nov 21, 2025
82 future.com.bo future.com.bo BO Nov 19, 2025
83 MCC mcchemical.com 🇺🇸 United States Manufacturing Nov 19, 2025
84 ****clinic.com.** Healthcare Nov 17, 2025
85 f*t*r*.com.** Nov 17, 2025
86 ctfc.cat ctfc.cat 🇪🇸 Spain Nov 12, 2025
87 omniumint omniumint.com 🇺🇸 United States Nov 11, 2025
88 www.oucru.org www.oucru.org 🇻🇳 Vietnam Education Nov 5, 2025
89 www.heitech.com.my www.heitech.com.my 🇲🇾 Malaysia Technology Nov 4, 2025
90 juntalocal.cdmx.gob.mx juntalocal.cdmx.gob.mx 🇲🇽 Mexico Public Sector Nov 1, 2025
91 m*c*e*ic*l.com Healthcare Nov 1, 2025
92 o*c*u.o** Technology Nov 1, 2025
93 fhw.org fhw.org 🇺🇸 United States Healthcare Oct 28, 2025
94 g*e*g*o**l.com Technology Oct 28, 2025
95 h*i**c*.c*m.my Oct 28, 2025
96 h*tel*ys*e*s.pl Hospitality and Tourism Oct 28, 2025
97 r*p**fl*wa*ps.com Technology Oct 28, 2025
98 pharmaciedesalize.com.fr pharmaciedesalizes.fr 🇫🇷 France Healthcare Oct 17, 2025
99 www.o****m*nt.com Oct 16, 2025
100 EMBASY OF BOLIVIA DC boliviawdc.org BO Public Sector Oct 15, 2025

Frequently Asked Questions

What is Devman ransomware?

Devman is a ransomware threat group that has claimed 184 victims since its first known activity in April 2025. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Devman attacked?

Devman has claimed 184 victims in our database, representing 0.9% of all tracked ransomware attacks. The most targeted countries are United States, France, Taiwan, SJ.

Which countries does Devman target?

Devman has attacked organizations in 39 countries. The top targeted countries are: United States, France, Taiwan, SJ.

Which industries does Devman target?

Devman most frequently targets the Healthcare, Technology, Financial Services sectors based on victim disclosures in our database.

Is Devman still active?

Devman's most recent victim disclosure in our database was on February 4, 2026. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.