How not to run a RaaS Operation
ID: 60d1ea9e-4208-5c87-93ab-ae0cb2373bef
STIX ID: report--60d1ea9e-4208-5c87-93ab-ae0cb2373bef
Feed Name: Ctrl-Alt-Int3l
Threat Score
Devman is a Russian-speaking ransomware operator attempting to operate a RaaS platform whose poor OPSEC led to multiple Rocket.Chat breaches; leaked communications reveal affiliate coordination, victim assignments (including healthcare and police), use of FortiGate/LDAP for initial access, a DragonForce-derived ransomware build, Sliver C2 usage, and multiple IOCs (notably 203.91.74.97 and 86.106.85.183).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
