logo

How not to run a RaaS Operation

ID: 60d1ea9e-4208-5c87-93ab-ae0cb2373bef

STIX ID: report--60d1ea9e-4208-5c87-93ab-ae0cb2373bef

Feed Name: Ctrl-Alt-Int3l

Threat Score
72/100

Date Published: 2025-12-16

Date Updated: 2026-04-19

Author: Ctrl-Alt-Intel

...
...

Devman is a Russian-speaking ransomware operator attempting to operate a RaaS platform whose poor OPSEC led to multiple Rocket.Chat breaches; leaked communications reveal affiliate coordination, victim assignments (including healthcare and police), use of FortiGate/LDAP for initial access, a DragonForce-derived ransomware build, Sliver C2 usage, and multiple IOCs (notably 203.91.74.97 and 86.106.85.183).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.