
ANY.RUN Releases Technical Analysis Of DEVMAN Ransomware Built On Dragonforce Raas
DUBAI, DUBAI, UNITED ARAB EMIRATES, July 1, 2025 /EINPresswire / -- ANY , a trusted provider of cybersecurity solutions, has published a new technical analysis revealing a ransomware variant that blends traits of DragonForce and Conti families with indicators of a newer actor known as DEVMAN.
DEVMAN: A New Threat Actor Targeting Enterprises
DEVMAN is a relatively new actor has recently emerged under this name, featuring its own Dedicated Leak Site (DLS) called Devman's Place, a separate infrastructure, and nearly 40 claimed victims, primarily in Asia and Africa, with occasional incidents in Latin America and Europe.
DEVMAN Ransomware: A Hybrid Threat
The analyzed sample, initially labeled as DragonForce by antivirus engines, was revealed to be a lightly modified build. It appends the“.DEVMAN” extension to encrypted files, scrambles filenames using a deterministic function, and, due to a builder flaw, encrypts its own ransom notes before victims can read them.
Key Findings of the DEVMAN Analysis Include:
· Local execution: No external C2 traffic was detected; all behavior is confined to the local system.
· SMB probing: The sample attempts to access hardcoded SMB shares such as ADMIN$.
· Conti-style persistence: The use of mutexes and the Windows Restart Manager mirrors tactics from Conti and DragonForce campaigns.
To explore the full technical breakdown and see how DEVMAN behaves inside the sandbox, visit the ANY blog .
About ANY
ANY offers a comprehensive suite of cybersecurity solutions, including their Interactive Sandbox and advanced Threat Intelligence services. Trusted by over 15,000 companies worldwide, ANY enables dynamic malware analysis across Windows, Linux, and Android systems.
In addition to sandboxing, ANY provides Threat Intelligence Lookup, Feeds, and YARA Search, helping security teams detect, investigate, and respond to threats with greater speed and accuracy.
The ANY team
ANYRUN FZCO
+1 657-366-5050
email us here
Visit us on social media:
LinkedIn
YouTube
X
Legal Disclaimer:
EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Legal Disclaimer:
MENAFN provides the
information “as is” without warranty of any kind. We do not accept
any responsibility or liability for the accuracy, content, images,
videos, licenses, completeness, legality, or reliability of the information
contained in this article. If you have any complaints or copyright
issues related to this article, kindly contact the provider above.
Most popular stories
Market Research

- Ethereum-Based Defi Crypto Mutuum Finance (MUTM) Reaches 50% Completion In Phase 6
- Casper (CSPR) Is Listed On Gate As Part Of Continued U.S. Market Expansion
- Ethereum-Based Defi Crypto Mutuum Finance (MUTM) Raises Over $16 Million With More Than 720M Tokens Sold
- Tokenfi And New To The Street Announce National Media Partnership To Reach 219M+ Households
- Flexm Recognized As“Highly Commended” In The Regtech Category At The Asia Fintech Awards Singapore 2025
- Forex Expo Dubai 2025 Conference To Feature 150+ Global FX And Fintech Leaders
Comments
No comment