logo

From Conti to Black Basta to DevMan: The Endless Ransomware Rebrand by Lucie Cardiet

ID: ff369b2e-e7ed-58e8-b47c-0c75b8680c65

STIX ID: report--ff369b2e-e7ed-58e8-b47c-0c75b8680c65

Feed Name: Vectra AI Blog

Threat Score
75/100

Date Published: 2025-10-17

Date Updated: 2026-05-01

...
...

This report analyzes DevMan, a 2025 ransomware operator that reuses DragonForce/Conti-derived code and has evolved into a Ransomware-as-a-Service (DevMan 2.0) offering builders, affiliate dashboards, and automated exfiltration; it details DevMan’s technical traits (.DEVMAN extension, offline SMB-focused encryption, multiple modes), its affiliate-driven business model, and emphasizes that attribution is difficult while defenders should focus on behavioral detection rather than signatures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.