How not to run a RaaS Operation
ID: 32d54740-2083-5e35-a07b-4dc285f88994
STIX ID: report--32d54740-2083-5e35-a07b-4dc285f88994
Feed Name: Ctrl-Alt-Int3l
Threat Score
Devman is a Russian-speaking ransomware operator transitioning to a public RaaS built from modified DragonForce code; leaked Rocket.Chat chats and public artifacts reveal affiliate management, active victim networks (including police and healthcare), use of FortiGate/LDAP initial access and Sliver C2, and exposed infrastructure (notable IPs and leak sites) due to poor OPSEC.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
