Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Devman / Devman 2.0

Parent: ransomhub

| RaaS

Former RansomHub and INC Ransom affiliate.

Victims
184
 
First Discovered
2025-04-06
victim
Last Discovered
2026-02-04
victim
Inactive Since
97
days
Avg Delay
27.2
days
Infostealer
21.5%
victims with domain
Countries
39
hit
View Victims on World Map View Group Statistics
Attack Velocity — Last 12 months

Known Locations (3)
Favicon Title Type Available Last Visit Server Info FQDN
favicon Devman's Place No 2026-04-28T07:23:36 qljmlmp4psnn3wqskkf3alqquatymo6hntficb4rhq5n76kuogcv7zyd.onion
favicon DEVMAN 2.0 - Leaked Data No 2026-04-28T07:26:11 wugurgyscp5rxpihef5vl6b6m5ont3b6sezhl7boboso2enib2k3q6qd.onion
favicon Devman Ransomware No 2026-04-28T07:28:43 devmanblggk7ddrtqj3tsocnayow3bwnozab2s4yhv4shpv6ueitjzid.onion

Target
Top 5 Activity Sectors
  • Healthcare 28
  • Technology 24
  • Financial Services 16
  • Public Sector 14
  • Business Services 12
Top 5 Countries
  • US flag United States 44
  • FR flag France 9
  • SJ flag Svalbard and Jan Mayen 7
  • TW flag Taiwan, Province of China 7
  • BR flag Brazil 6

Heatmap

Ransom Notes (1)

TTPs Matrix (11)
This information is provided by Crocodyli & Ransomware.live
Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Exfiltration Impact
Valid Accounts PowerShell Valid Accounts Exploitation for Privilege Escalation Masquerading OS Credential Dumping Remote System Discovery SMB/Windows Admin Shares Data from Local System Exfiltration Over C2 Channel Data Encrypted for Impact
Exploitation of Remote Services Exploitation for Client Execution     Disable or Modify Tools   Network Service Scanning       Service Stop
            System Information Discovery       Inhibit System Recovery
                    Defacement

YARA Rules (1)

Indicators of Compromise (IoCs) (5)
IP Address 3 tox 1 twitter 1
Type IOC
IP Address 38.132.122.213
IP Address 38.132.122.214
IP Address 83.217.209.210
tox 9D97F166730F865F793E2EA07B173C742A6302879DE1B0BBB03817A5A04B572FBD82F984981D
twitter @Inifintyink

Victims (184)
Logo
Discovered: 2026-02-04 (3mo ago)  ·  Attack est.: 2026-02-03
SSN, medical data, medical cards…
Logo
Discovered: 2026-02-02 (3mo ago)
Finance documents, clients PII…
Logo
Discovered: 2026-01-30 (3mo ago)
Patient data, med cards…
Logo
Discovered: 2026-01-30 (3mo ago)
[AI generated] N/A…
Logo
Discovered: 2026-01-29 (3mo ago)  ·  Attack est.: 2026-01-26
The data contains materials of national security including BIO laboratory facilities blue prints, an…
Logo
Discovered: 2026-01-29 (3mo ago)  ·  Attack est.: 2026-01-28
PII data, SSN´s financial and audit reports.…
Logo
Discovered: 2026-01-28 (3mo ago)  ·  Attack est.: 2026-01-26
Client data, HR data…
Logo
Discovered: 2026-01-28 (3mo ago)
No description available
Logo
Discovered: 2026-01-28 (3mo ago)
[AI generated] TIW Group is a specialist software firm with over 30 years of experience in developin…
Logo
Discovered: 2026-01-28 (3mo ago)
PII data, SSN´s financial and audit reports.…
Logo
Discovered: 2026-01-27 (3mo ago)
[AI generated] TWI Group is a specialized freight forwarder and logistics provider that primarily fo…
Logo
Discovered: 2026-01-26 (3mo ago)
The data contains materials of national security including BIO laboratory facilities blue prints, an…
Logo
Discovered: 2026-01-26 (3mo ago)  ·  Attack est.: 2026-01-25
Insurance data, Hr data, client data…
Logo
Discovered: 2026-01-25 (3mo ago)
No description available
Logo
Discovered: 2026-01-24 (3mo ago)
Patient data, medical cards clinic records…
Logo
Discovered: 2026-01-24 (3mo ago)
No description available
Logo
Discovered: 2026-01-21 (3mo ago)  ·  Attack est.: 2026-01-20
[AI generated] AutoMax.com is a leading used car dealership group in the US. Known for its wide rang…
Logo
Discovered: 2026-01-21 (3mo ago)  ·  Attack est.: 2026-01-20
[AI generated] N/A…
Logo
Discovered: 2026-01-21 (3mo ago)  ·  Attack est.: 2026-01-20
No description available
Logo
Discovered: 2026-01-21 (3mo ago)  ·  Attack est.: 2026-01-20
No description available
Logo
Discovered: 2026-01-21 (3mo ago)
No description available
Logo
Discovered: 2026-01-21 (3mo ago)
[AI generated] Mims.com is an online resource for medical professionals used mainly in Asia-Pacific …
Logo
Discovered: 2026-01-21 (3mo ago)
[AI generated] N/A…
Logo
Discovered: 2026-01-20 (3mo ago)
[AI generated] Tvgoiania is a media and news company based in Goiânia, Brazil. It provides a platfor…
Logo
Discovered: 2026-01-12 (3mo ago)
[AI generated] N/A…
Logo
Discovered: 2026-01-12 (4mo ago)
Financial, contracts HR data…
Logo
Discovered: 2026-01-12 (4mo ago)  ·  Attack est.: 2026-01-11
[AI generated] Consigaz is a Brazilian company that specializes in the distribution of Liquefied Pet…
Logo
Discovered: 2026-01-12 (4mo ago)  ·  Attack est.: 2026-01-11
Datatheft 300gb of data stollen includes gov documents, deeds and much more…
Logo
Discovered: 2026-01-12 (4mo ago)  ·  Attack est.: 2026-01-11
data theft, evidence, officers personal information police reports, DEA open cases information…
Logo
Discovered: 2026-01-12 (4mo ago)  ·  Attack est.: 2026-01-11
Patients data, plastic operations data, SSNs…
Logo
Discovered: 2026-01-12 (4mo ago)
Financial, patients data, HR data…
Logo
Discovered: 2026-01-12 (4mo ago)
Case data, atourney client data, hr data…
Logo
Discovered: 2025-12-28 (4mo ago)  ·  Attack est.: 2025-12-25
Financial, Hr documents, claims…
Logo
Discovered: 2025-12-28 (4mo ago)  ·  Attack est.: 2025-12-27
Patients data, financial data…
Logo
Discovered: 2025-12-28 (4mo ago)  ·  Attack est.: 2025-12-27
Financial data, HR data…
Logo
Discovered: 2025-12-28 (4mo ago)
Financial, Custommer data…
Logo
Discovered: 2025-12-25 (4mo ago)
HR data…
Logo
Discovered: 2025-12-25 (4mo ago)
Financial, Hr documents, claims…
Logo
Discovered: 2025-12-25 (4mo ago)
Hr data, client data…
Logo
Discovered: 2025-12-22 (4mo ago)  ·  Attack est.: 2025-12-18
Patients' full records, HIV test results, IDs. Throughout a long waiting period, and despite a vast…
Logo
Discovered: 2025-12-22 (4mo ago)
HR data…
Logo
Discovered: 2025-12-22 (4mo ago)  ·  Attack est.: 2025-12-19
Financial, Client IDS…
Logo
Discovered: 2025-12-22 (4mo ago)
Passport scans, Financial…
Logo
Discovered: 2025-12-19 (4mo ago)
Financial, HR data…
Logo
Discovered: 2025-12-19 (4mo ago)
SRC, Client data…
Logo
Discovered: 2025-12-19 (4mo ago)
Financial, Client IDS…
Logo
Discovered: 2025-12-19 (4mo ago)  ·  Attack est.: 2025-12-17
[AI generated] N/A…
Logo
Discovered: 2025-12-18 (4mo ago)  ·  Attack est.: 2025-12-16
Financial, HR…
Logo
Discovered: 2025-12-18 (4mo ago)
Patients full records, HIV tests results, ID's…
Logo
Discovered: 2025-12-17 (4mo ago)  ·  Attack est.: 2025-12-16
Financial, HR data, Client data…
Logo
Discovered: 2025-12-17 (4mo ago)
No description available
Logo
Discovered: 2025-12-16 (4mo ago)  ·  Attack est.: 2025-12-10
HR data, clients data, Financial data…
Logo
Discovered: 2025-12-16 (4mo ago)
Financial, HR data, Client data…
Logo
Discovered: 2025-12-16 (4mo ago)
Financial, HR…
Logo
Discovered: 2025-12-15 (4mo ago)  ·  Attack est.: 2025-12-14
[AI generated] N/A…
Logo
Discovered: 2025-12-14 (4mo ago)  ·  Attack est.: 2025-12-11
Financial data, clients data…
Logo
Discovered: 2025-12-14 (4mo ago)
No description available
Logo
Discovered: 2025-12-12 (5mo ago)  ·  Attack est.: 2025-12-10
Employee data, hr info, projects, Work logs of the power plants, Scada SRC…
Logo
Discovered: 2025-12-12 (5mo ago)  ·  Attack est.: 2025-12-11
[AI generated] Hopital La Rabta is a major hospital located in Tunis, Tunisia. It provides a wide ar…
Logo
Discovered: 2025-12-11 (5mo ago)
No description available
Logo
Discovered: 2025-12-11 (5mo ago)
Financial data, clients data…
Logo
Discovered: 2025-12-11 (5mo ago)
Data theft 80gb…
Logo
Discovered: 2025-12-09 (5mo ago)  ·  Attack est.: 2025-12-06
patient data…
Logo
Discovered: 2025-12-09 (5mo ago)  ·  Attack est.: 2025-12-06
Financial Records, Med cards, Hr documents…
Logo
Discovered: 2025-12-09 (5mo ago)  ·  Attack est.: 2025-12-08
Full quickbooks dump, patients data, and financial data…
Logo
Discovered: 2025-12-07 (5mo ago)  ·  Attack est.: 2025-12-06
[AI generated] Solidere, short for Société Libanaise de Développement et Reconstruction, is a Lebane…
Logo
Discovered: 2025-12-07 (5mo ago)  ·  Attack est.: 2025-12-06
Financial data, medical records…
Logo
Discovered: 2025-12-07 (5mo ago)  ·  Attack est.: 2025-12-06
Financial Records, Med cards, Hr documents…
Logo
Discovered: 2025-12-07 (5mo ago)  ·  Attack est.: 2025-12-06
Datatheft Client DB…
Logo
Discovered: 2025-12-07 (5mo ago)  ·  Attack est.: 2025-12-06
Financial data, medical cards…
Logo
Discovered: 2025-12-03 (5mo ago)
Ransom: 200gb 150k…
Logo
Discovered: 2025-12-02 (5mo ago)
Ransom: 200gb 220k…
Logo
Discovered: 2025-12-02 (5mo ago)
Ransom: 75k 50gb…
Logo
Discovered: 2025-12-01 (5mo ago)
Ransom: ecaretest.com 350k 246gb…
Logo
Discovered: 2025-12-01 (5mo ago)  ·  Attack est.: 2023-06-07
Ransom: 90k 236gb…
Logo
Discovered: 2025-12-01 (5mo ago)
Ransom: 550k 280gb…
Logo
Discovered: 2025-12-01 (5mo ago)
Ransom: 75k 50gb…
Logo
Discovered: 2025-12-01 (5mo ago)
Ransom: 200gb 150k…
Logo
Discovered: 2025-12-01 (5mo ago)
Ransom: 250k 200gb…
Logo
Discovered: 2025-11-21 (5mo ago)
Ransom: 500gb 400k…
Logo
Discovered: 2025-11-21 (5mo ago)
Ransom: data theft 40gb 120K…
Logo
Discovered: 2025-11-19 (5mo ago)
Ransom: 200k 120gb…
Logo
Discovered: 2025-11-19 (5mo ago)
Ransom: 200k 80gb…
Logo
Discovered: 2025-11-17 (5mo ago)
Ransom: 300k 120gb…
Logo
Discovered: 2025-11-17 (5mo ago)
Ransom: 210k 145gb…
Logo
Discovered: 2025-11-12 (6mo ago)
Ransom: 248000 30gb of files exfiltrated…
Logo
Discovered: 2025-11-11 (6mo ago)
Ransom: 1.2million 1.2 tb and one very interesting email…
Logo
Discovered: 2025-11-05 (6mo ago)
Ransom: 500k 120gb…
Logo
Discovered: 2025-11-04 (6mo ago)
Ransom: 500k 60gb…
Logo
Discovered: 2025-11-01 (6mo ago)
Ransom: 50gb 100k…
Logo
Discovered: 2025-11-01 (6mo ago)
Ransom: 500k 120gb…
Logo
Discovered: 2025-11-01 (6mo ago)
Ransom: 60gb 300k…
Logo
Discovered: 2025-10-28 (6mo ago)
Ransom: data theft 400k…
Logo
Discovered: 2025-10-28 (6mo ago)
Ransom: 700k 120gb…
Logo
Discovered: 2025-10-28 (6mo ago)
Ransom: 500k 60gb…
Logo
Discovered: 2025-10-28 (6mo ago)
Ransom: oracle theft 200k…
Logo
Discovered: 2025-10-28 (6mo ago)
Ransom: oracle theft 400k…
Logo
Discovered: 2025-10-17 (6mo ago)
Ransom: 50k 80gb…
Logo
Discovered: 2025-10-16 (6mo ago)
Ransom: 1400000 USD…
Logo
Discovered: 2025-10-15 (6mo ago)
Ransom: 200k 400gb…
Logo
Discovered: 2025-10-15 (6mo ago)
Ransom: 200k 300gb…
Logo
Discovered: 2025-10-14 (6mo ago)
Ransom: 200000 USD…
Logo
Discovered: 2025-10-10 (7mo ago)
Ransom: 250k 300gb…
Logo
Discovered: 2025-10-10 (7mo ago)
Ransom: 200000 USD…
Logo
Discovered: 2025-10-06 (7mo ago)
Ransom: 550000 USD…
Logo
Discovered: 2025-10-03 (7mo ago)
Ransom: 370k 80gb…
Logo
Discovered: 2025-10-03 (7mo ago)
Ransom: 6kk 400gb exfiltrated…
Logo
Discovered: 2025-10-01 (7mo ago)
Ransom: 50000 USD…
Logo
Discovered: 2025-10-01 (7mo ago)
Ransom: 50000 USD…
Logo
Discovered: 2025-10-01 (7mo ago)
Ransom: 500000 USD…
Logo
Discovered: 2025-10-01 (7mo ago)
Ransom: 150000 USD…
Logo
Discovered: 2025-09-30 (7mo ago)
Ransom: 780000 USD…
Logo
Discovered: 2025-09-29 (7mo ago)
Ransom: 120000 USD | Note: 300gb exfiltrated…
Logo
Discovered: 2025-09-29 (7mo ago)
Ransom: 580000 USD…
Logo
Discovered: 2025-09-29 (7mo ago)
Ransom: 590000 USD…
Logo
Discovered: 2025-09-29 (7mo ago)
Ransom: 350000 USD | Note: 400gb stollen…
Logo
Discovered: 2025-09-29 (7mo ago)
Ransom: 100000 USD…
Logo
Discovered: 2025-09-29 (7mo ago)
Ransom: 590000 USD…
Logo
Discovered: 2025-09-29 (7mo ago)
Ransom: 100000 USD…
Logo
Discovered: 2025-09-15 (7mo ago)
91000000 USD…
Logo
Discovered: 2025-09-15 (7mo ago)
1700000 USD…
Logo
Discovered: 2025-09-06 (8mo ago)
91000000 USD…
Logo
Discovered: 2025-09-03 (8mo ago)
1000000 USD…
Logo
Discovered: 2025-09-03 (8mo ago)
5000000 USD…
Logo
Discovered: 2025-08-04 (9mo ago)
1000000 USD…
Logo
Discovered: 2025-08-04 (9mo ago)
1800000 USD…
Logo
Discovered: 2025-08-01 (9mo ago)
1000000 USD…
Logo
Discovered: 2025-08-01 (9mo ago)
1050000 USD…
Logo
Discovered: 2025-08-01 (9mo ago)
1100000 USD…
Logo
Discovered: 2025-08-01 (9mo ago)
6000000 USD…
Logo
Discovered: 2025-07-20 (9mo ago)
4000000 USD…
Logo
Discovered: 2025-07-18 (9mo ago)
4000000 USD…
Logo
Discovered: 2025-07-17 (9mo ago)
15000000 USD…
Logo
Discovered: 2025-07-15 (10mo ago)
2270000 USD…
Logo
Discovered: 2025-07-13 (10mo ago)
2270000 USD…
Logo
Discovered: 2025-07-12 (10mo ago)
7250000 USD…
Logo
Discovered: 2025-07-05 (10mo ago)
(To be disclosed)...…
Logo
Discovered: 2025-07-05 (10mo ago)
450000 USD…
Logo
Discovered: 2025-07-05 (10mo ago)
TBD...…
Logo
Discovered: 2025-07-05 (10mo ago)
1000000 USD…
Logo
Discovered: 2025-07-05 (10mo ago)
1000000 USD…
Logo
Discovered: 2025-07-05 (10mo ago)
10000000 USD…
Logo
Discovered: 2025-07-05 (10mo ago)
6450000 USD…
Logo
Discovered: 2025-06-02 (11mo ago)
TBD…
Logo
Discovered: 2025-05-31 (11mo ago)
1.1 million USD…
Logo
Discovered: 2025-05-26 (11mo ago)
130k USD…
Logo
Discovered: 2025-05-26 (11mo ago)
TBD…
Logo
Discovered: 2025-05-25 (11mo ago)
TBD…
Logo
Discovered: 2025-05-23 (11mo ago)
200k USD…
Logo
Discovered: 2025-05-23 (11mo ago)
1.2 million USD…
Logo
Discovered: 2025-05-19 (11mo ago)
4.5 million USD…
Logo
Discovered: 2025-05-19 (11mo ago)
TBD…
Logo
Discovered: 2025-05-19 (11mo ago)
TBD…
Logo
Discovered: 2025-05-19 (11mo ago)
TBD…
Logo
Discovered: 2025-05-19 (11mo ago)
120k…
Logo
Discovered: 2025-05-19 (11mo ago)
TBD…
Logo
Discovered: 2025-05-19 (11mo ago)
383K USD…
Logo
Discovered: 2025-05-11 (1y ago)
80K USD…
Logo
Discovered: 2025-05-10 (1y ago)
590K USD…
Logo
Discovered: 2025-05-10 (1y ago)
TBD…
Logo
Discovered: 2025-05-09 (1y ago)
375K USD…
Logo
Discovered: 2025-05-07 (1y ago)
2.5 million USD…
Logo
Discovered: 2025-05-05 (1y ago)
100K USD…
Logo
Discovered: 2025-05-02 (1y ago)
375K USD…
Logo
Discovered: 2025-05-01 (1y ago)
TBD…
Logo
Discovered: 2025-05-01 (1y ago)
TBD…
Logo
Discovered: 2025-05-01 (1y ago)
TBD…
Logo
Discovered: 2025-05-01 (1y ago)
TBD…
Logo
Discovered: 2025-05-01 (1y ago)
550k USD…
Logo
Discovered: 2025-04-25 (1y ago)
(To be discoled)…
Logo
Discovered: 2025-04-20 (1y ago)
(90k USD)…
Logo
Discovered: 2025-04-20 (1y ago)
60k USD…
Logo
Discovered: 2025-04-20 (1y ago)
(To be discoled)…
Logo
Discovered: 2025-04-20 (1y ago)
(To be discoled)…
Logo
Discovered: 2025-04-20 (1y ago)
450k USD…
Logo
Discovered: 2025-04-13 (1y ago)
70k USD…
Logo
Discovered: 2025-04-13 (1y ago)
Price -Soon…
Logo
Discovered: 2025-04-13 (1y ago)
200k USD…
Logo
Discovered: 2025-04-13 (1y ago)
150k USD…
Logo
Discovered: 2025-04-06 (1y ago)
Different Locker…
Logo
Discovered: 2025-04-06 (1y ago)
Name disclosed soon…
Logo
Discovered: 2025-04-06 (1y ago)
Pending…
Logo
Discovered: 2025-04-06 (1y ago)  ·  Attack est.: 2025-03-22
Still in negotiation…