logo

New DEVMAN Ransomware by DragonForce Targets Windows 10 and 11 Users

ID: 22ce8fef-69c1-5ff7-88a2-34510d743cca

STIX ID: report--22ce8fef-69c1-5ff7-88a2-34510d743cca

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2025-07-01

Date Updated: 2026-04-13

Author: Mandvi

...
...

The report analyzes DEVMAN, a ransomware variant linked to the DragonForce/Conti ecosystem that encrypts Windows 10/11 systems (appending .DEVMAN), probes SMB for lateral movement, and uses Restart Manager interactions and mutexes for persistence; notable quirks include a builder flaw that frequently encrypts its own ransom notes, and the sample is associated with a dedicated leak site and nearly 40 victims in Asia and Africa.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.