logo

How not to run a RaaS Operation

ID: 32d54740-2083-5e35-a07b-4dc285f88994

STIX ID: report--32d54740-2083-5e35-a07b-4dc285f88994

Feed Name: Ctrl-Alt-Int3l

Threat Score
70/100

Date Published: 2025-12-16

Date Updated: 2026-04-19

Author: Ctrl-Alt-Int3l

...
...

Devman is a Russian-speaking ransomware operator transitioning to a public RaaS built from modified DragonForce code; leaked Rocket.Chat chats and public artifacts reveal affiliate management, active victim networks (including police and healthcare), use of FortiGate/LDAP initial access and Sliver C2, and exposed infrastructure (notable IPs and leak sites) due to poor OPSEC.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.