Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Devman / Devman 2.0 | Parent: ransomhub

| Active | RaaS

Former RansomHub and INC Ransom affiliate.

Victims
187
 
First Discovered
2025-04-06
victim
Last Discovered
2026-02-04
victim
Inactive Since
57
days
Avg Delay
27.2
days
Infostealer
20.5%
victims with domain

View Victims on World Map

View group statistics


Known Locations (3)
Favicon Title Type Available Last Visit Server Info FQDN
favicon Devman's Place No 2025-07-16 03:00:28 qljmlmp4psnn3wqskkf3alqquatymo6hntficb4rhq5n76kuogcv7zyd.onion
favicon DEVMAN 2.0 - Leaked Data No 2025-10-29 08:30:31 wugurgyscp5rxpihef5vl6b6m5ont3b6sezhl7boboso2enib2k3q6qd.onion
favicon Devman Ransomware No 2026-03-18 07:00:37 devmanblggk7ddrtqj3tsocnayow3bwnozab2s4yhv4shpv6ueitjzid.onion

Target (Available)
Top 5 Activity Sectors
  • Technology 25
  • Healthcare 20
  • Public Sector 12
  • Construction 7
  • Agriculture and Food Production 6
Top 5 Countries
  • US flag United States 39
  • FR flag France 9
  • TW flag Taiwan, Province of China 7
  • SJ flag Svalbard and Jan Mayen 7
  • TH flag Thailand 6

Heatmap (Available)

Ransom Notes (1)

Tools Used (Not Available)

No tools used available.


Vulnerabilities Exploited (0)

No vulnerabilities exploited available.


TTPs Matrix (11)
This information is provided by Crocodyli & Ransomware.live
Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Exfiltration Impact
Exploitation of Remote Services PowerShell Valid Accounts Exploitation for Privilege Escalation Masquerading OS Credential Dumping Remote System Discovery SMB/Windows Admin Shares Data from Local System Exfiltration Over C2 Channel Data Encrypted for Impact
Valid Accounts Exploitation for Client Execution     Disable or Modify Tools   Network Service Scanning       Inhibit System Recovery
            System Information Discovery       Service Stop
                    Defacement

Negotiation Chats (0)

No negotiation chats available.


YARA Rules (0)

No YARA rules available.


Indicators of Compromise (IoCs) (5)
IP 3 TOX 1 TWITTER 1
Type IOC
ip 83.217.209.210
ip 38.132.122.213
ip 38.132.122.214
tox 9D97F166730F865F793E2EA07B173C742A6302879DE1B0BBB03817A5A04B572FBD82F984981D
twitter @Inifintyink

Victims (187)
Logo
Discovered: 2026-02-04  ·  Attack est.: 2026-02-03
SSN, medical data, medical cards…
Logo
Discovered: 2026-02-02
Finance documents, clients PII…
Logo
Discovered: 2026-01-30
Patient data, med cards…
Logo
Discovered: 2026-01-30
[AI generated] N/A…
Logo
Discovered: 2026-01-29  ·  Attack est.: 2026-01-26
The data contains materials of national security including BIO laboratory facilities blue prints, an…
Logo
Discovered: 2026-01-29  ·  Attack est.: 2026-01-28
PII data, SSN´s financial and audit reports.…
Logo
Discovered: 2026-01-28  ·  Attack est.: 2026-01-26
Client data, HR data…
Logo
Discovered: 2026-01-28
No description available
Logo
Discovered: 2026-01-28
[AI generated] TIW Group is a specialist software firm with over 30 years of experience in developin…
Logo
Discovered: 2026-01-28
PII data, SSN´s financial and audit reports.…
Logo
Discovered: 2026-01-27
[AI generated] TWI Group is a specialized freight forwarder and logistics provider that primarily fo…
Logo
Discovered: 2026-01-26
The data contains materials of national security including BIO laboratory facilities blue prints, an…
Logo
Discovered: 2026-01-26  ·  Attack est.: 2026-01-25
Insurance data, Hr data, client data…
Logo
Discovered: 2026-01-25
No description available
Logo
Discovered: 2026-01-24
Patient data, medical cards clinic records…
Logo
Discovered: 2026-01-24
No description available
Logo
Discovered: 2026-01-21  ·  Attack est.: 2026-01-20
[AI generated] AutoMax.com is a leading used car dealership group in the US. Known for its wide rang…
Logo
Discovered: 2026-01-21  ·  Attack est.: 2026-01-20
[AI generated] N/A…
Logo
Discovered: 2026-01-21  ·  Attack est.: 2026-01-20
No description available
Logo
Discovered: 2026-01-21  ·  Attack est.: 2026-01-20
No description available
Logo
Discovered: 2026-01-21
No description available
Logo
Discovered: 2026-01-21
[AI generated] Mims.com is an online resource for medical professionals used mainly in Asia-Pacific …
Logo
Discovered: 2026-01-21
[AI generated] N/A…
Logo
Discovered: 2026-01-20
[AI generated] Tvgoiania is a media and news company based in Goiânia, Brazil. It provides a platfor…
Logo
Discovered: 2026-01-12
[AI generated] N/A…
Logo
Discovered: 2026-01-12
Financial, contracts HR data…
Logo
Discovered: 2026-01-12  ·  Attack est.: 2026-01-11
[AI generated] Consigaz is a Brazilian company that specializes in the distribution of Liquefied Pet…
Logo
Discovered: 2026-01-12  ·  Attack est.: 2026-01-11
Datatheft 300gb of data stollen includes gov documents, deeds and much more…
Logo
Discovered: 2026-01-12  ·  Attack est.: 2026-01-11
data theft, evidence, officers personal information police reports, DEA open cases information…
Logo
Discovered: 2026-01-12  ·  Attack est.: 2026-01-11
Patients data, plastic operations data, SSNs…
Logo
Discovered: 2026-01-12
Financial, patients data, HR data…
Logo
Discovered: 2026-01-12
Case data, atourney client data, hr data…
Logo
Discovered: 2025-12-28  ·  Attack est.: 2025-12-25
Financial, Hr documents, claims…
Logo
Discovered: 2025-12-28  ·  Attack est.: 2025-12-27
Patients data, financial data…
Logo
Discovered: 2025-12-28  ·  Attack est.: 2025-12-27
Financial data, HR data…
Logo
Discovered: 2025-12-28
Financial, Custommer data…
Logo
Discovered: 2025-12-25
HR data…
Logo
Discovered: 2025-12-25
Financial, Hr documents, claims…
Logo
Discovered: 2025-12-25
Hr data, client data…
Logo
Discovered: 2025-12-22  ·  Attack est.: 2025-12-18
Patients' full records, HIV test results, IDs. Throughout a long waiting period, and despite a vast…
Logo
Discovered: 2025-12-22
HR data…
Logo
Discovered: 2025-12-22  ·  Attack est.: 2025-12-19
Financial, Client IDS…
Logo
Discovered: 2025-12-22
Passport scans, Financial…
Logo
Discovered: 2025-12-19
Financial, HR data…
Logo
Discovered: 2025-12-19
SRC, Client data…
Logo
Discovered: 2025-12-19
Financial, Client IDS…
Logo
Discovered: 2025-12-19  ·  Attack est.: 2025-12-17
[AI generated] N/A…
Logo
Discovered: 2025-12-18  ·  Attack est.: 2025-12-16
Financial, HR…
Logo
Discovered: 2025-12-18
Patients full records, HIV tests results, ID's…
Logo
Discovered: 2025-12-17  ·  Attack est.: 2025-12-16
Financial, HR data, Client data…
Logo
Discovered: 2025-12-17
No description available
Logo
Discovered: 2025-12-16  ·  Attack est.: 2025-12-10
HR data, clients data, Financial data…
Logo
Discovered: 2025-12-16
Financial, HR data, Client data…
Logo
Discovered: 2025-12-16
Financial, HR…
Logo
Discovered: 2025-12-15  ·  Attack est.: 2025-12-14
[AI generated] N/A…
Logo
Discovered: 2025-12-14  ·  Attack est.: 2025-12-11
Financial data, clients data…
Logo
Discovered: 2025-12-14
No description available
Logo
Discovered: 2025-12-12  ·  Attack est.: 2025-12-10
Employee data, hr info, projects, Work logs of the power plants, Scada SRC…
Logo
Discovered: 2025-12-12  ·  Attack est.: 2025-12-11
[AI generated] Hopital La Rabta is a major hospital located in Tunis, Tunisia. It provides a wide ar…
Logo
Discovered: 2025-12-11
No description available
Logo
Discovered: 2025-12-11
Financial data, clients data…
Logo
Discovered: 2025-12-11
Data theft 80gb…
Logo
Discovered: 2025-12-09  ·  Attack est.: 2025-12-06
patient data…
Logo
Discovered: 2025-12-09  ·  Attack est.: 2025-12-06
Financial Records, Med cards, Hr documents…
Logo
Discovered: 2025-12-09  ·  Attack est.: 2025-12-08
Full quickbooks dump, patients data, and financial data…
Logo
Discovered: 2025-12-07  ·  Attack est.: 2025-12-06
[AI generated] Solidere, short for Société Libanaise de Développement et Reconstruction, is a Lebane…
Logo
Discovered: 2025-12-07  ·  Attack est.: 2025-12-06
Financial data, medical records…
Logo
Discovered: 2025-12-07  ·  Attack est.: 2025-12-06
Financial Records, Med cards, Hr documents…
Logo
Discovered: 2025-12-07  ·  Attack est.: 2025-12-06
Datatheft Client DB…
Logo
Discovered: 2025-12-07  ·  Attack est.: 2025-12-06
Financial data, medical cards…
Logo
Discovered: 2025-12-03
Ransom: 200gb 150k…
Logo
Discovered: 2025-12-02
Ransom: 200gb 220k…
Logo
Discovered: 2025-12-02
Ransom: 75k 50gb…
Logo
Discovered: 2025-12-01
Ransom: ecaretest.com 350k 246gb…
Logo
Discovered: 2025-12-01  ·  Attack est.: 2023-06-07
Ransom: 90k 236gb…
Logo
Discovered: 2025-12-01
Ransom: 550k 280gb…
Logo
Discovered: 2025-12-01
Ransom: 75k 50gb…
Logo
Discovered: 2025-12-01
Ransom: 200gb 150k…
Logo
Discovered: 2025-12-01
Ransom: 250k 200gb…
Logo
Discovered: 2025-11-21
Ransom: 500gb 400k…
Logo
Discovered: 2025-11-21
Ransom: data theft 40gb 120K…
Logo
Discovered: 2025-11-19
Ransom: 200k 120gb…
Logo
Discovered: 2025-11-19
Ransom: 200k 80gb…
Logo
Discovered: 2025-11-17
Ransom: 300k 120gb…
Logo
Discovered: 2025-11-17
Ransom: 210k 145gb…
Logo
Discovered: 2025-11-12
Ransom: 248000 30gb of files exfiltrated…
Logo
Discovered: 2025-11-11
Ransom: 1.2million 1.2 tb and one very interesting email…
Logo
Discovered: 2025-11-05
Ransom: 500k 120gb…
Logo
Discovered: 2025-11-04
Ransom: 500k 60gb…
Logo
Discovered: 2025-11-01
Ransom: 50gb 100k…
Logo
Discovered: 2025-11-01
Ransom: 500k 120gb…
Logo
Discovered: 2025-11-01
Ransom: 60gb 300k…
Logo
Discovered: 2025-10-28
Ransom: data theft 400k…
Logo
Discovered: 2025-10-28
Ransom: 700k 120gb…
Logo
Discovered: 2025-10-28
Ransom: 500k 60gb…
Logo
Discovered: 2025-10-28
Ransom: oracle theft 200k…
Logo
Discovered: 2025-10-28
Ransom: oracle theft 400k…
Logo
Discovered: 2025-10-17
Ransom: 50k 80gb…
Logo
Discovered: 2025-10-16
Ransom: 1400000 USD…
Logo
Discovered: 2025-10-15
Ransom: 200k 400gb…
Logo
Discovered: 2025-10-15
Ransom: 200k 300gb…
Logo
Discovered: 2025-10-14
Ransom: 200000 USD…
Logo
Discovered: 2025-10-10
Ransom: 250k 300gb…
Logo
Discovered: 2025-10-10
Ransom: 200000 USD…
Logo
Discovered: 2025-10-06
Ransom: 550000 USD…
Logo
Discovered: 2025-10-03
Ransom: 370k 80gb…
Logo
Discovered: 2025-10-03
Ransom: 6kk 400gb exfiltrated…
Logo
Discovered: 2025-10-01
Ransom: 50000 USD…
Logo
Discovered: 2025-10-01
Ransom: 50000 USD…
Logo
Discovered: 2025-10-01
Ransom: 500000 USD…
Logo
Discovered: 2025-10-01
Ransom: 150000 USD…
Logo
Discovered: 2025-09-30
Ransom: 780000 USD…
Logo
Discovered: 2025-09-29
Ransom: 120000 USD | Note: 300gb exfiltrated…
Logo
Discovered: 2025-09-29
Ransom: 580000 USD…
Logo
Discovered: 2025-09-29
Ransom: 590000 USD…
Logo
Discovered: 2025-09-29
Ransom: 350000 USD | Note: 400gb stollen…
Logo
Discovered: 2025-09-29
Ransom: 100000 USD…
Logo
Discovered: 2025-09-29
Ransom: 590000 USD…
Logo
Discovered: 2025-09-29
Ransom: 100000 USD…
Logo
Discovered: 2025-09-15
91000000 USD…
Logo
Discovered: 2025-09-15
1700000 USD…
Logo
Discovered: 2025-09-06
91000000 USD…
Logo
Discovered: 2025-09-03
1000000 USD…
Logo
Discovered: 2025-09-03
5000000 USD…
Logo
Discovered: 2025-08-04
1000000 USD…
Logo
Discovered: 2025-08-04
1800000 USD…
Logo
Discovered: 2025-08-01
1000000 USD…
Logo
Discovered: 2025-08-01
1050000 USD…
Logo
Discovered: 2025-08-01
1100000 USD…
Logo
Discovered: 2025-08-01
6000000 USD…
Logo
Discovered: 2025-07-20
4000000 USD…
Logo
Discovered: 2025-07-18
4000000 USD…
Logo
Discovered: 2025-07-17
15000000 USD…
Logo
Discovered: 2025-07-15
2270000 USD…
Logo
Discovered: 2025-07-13
2270000 USD…
Logo
Discovered: 2025-07-12
7250000 USD…
Logo
Discovered: 2025-07-05
(To be disclosed)...…
Logo
Discovered: 2025-07-05
450000 USD…
Logo
Discovered: 2025-07-05
TBD...…
Logo
Discovered: 2025-07-05
1000000 USD…
Logo
Discovered: 2025-07-05
1000000 USD…
Logo
Discovered: 2025-07-05
10000000 USD…
Logo
Discovered: 2025-07-05
6450000 USD…
Logo
Discovered: 2025-06-02
TBD…
Logo
Discovered: 2025-05-31
1.1 million USD…
Logo
Discovered: 2025-05-26
130k USD…
Logo
Discovered: 2025-05-25
TBD…
Logo
Discovered: 2025-05-23
200k USD…
Logo
Discovered: 2025-05-23
1.2 million USD…
Logo
Discovered: 2025-05-19
4.5 million USD…
Logo
Discovered: 2025-05-19
TBD…
Logo
Discovered: 2025-05-19
TBD…
Logo
Discovered: 2025-05-19
TBD…
Logo
Discovered: 2025-05-19
120k…
Logo
Discovered: 2025-05-19
TBD…
Logo
Discovered: 2025-05-19
383K USD…
Logo
Discovered: 2025-05-11
80K USD…
Logo
Discovered: 2025-05-10
590K USD…
Logo
Discovered: 2025-05-10
TBD…
Logo
Discovered: 2025-05-09
375K USD…
Logo
Discovered: 2025-05-07
2.5 million USD…
Logo
Discovered: 2025-05-05
100K USD…
Logo
Discovered: 2025-05-02
375K USD…
Logo
Discovered: 2025-05-01
TBD…
Logo
Discovered: 2025-05-01
TBD…
Logo
Discovered: 2025-05-01
TBD…
Logo
Discovered: 2025-05-01
550k USD…
Logo
Discovered: 2025-04-25
(To be discoled)…
Logo
Discovered: 2025-04-24
450k USD…
Logo
Discovered: 2025-04-20
(90k USD)…
Logo
Discovered: 2025-04-20
60k USD…
Logo
Discovered: 2025-04-20
(To be discoled)…
Logo
Discovered: 2025-04-20
(To be discoled)…
Logo
Discovered: 2025-04-20
450k USD…
Logo
Discovered: 2025-04-13
70k USD…
Logo
Discovered: 2025-04-13
Price -Soon…
Logo
Discovered: 2025-04-13
200k USD…
Logo
Discovered: 2025-04-13
150k USD…
Logo
Discovered: 2025-04-13
Amount TBD…
Logo
Discovered: 2025-04-13
590k USD…
Logo
Discovered: 2025-04-06
Different Locker…
Logo
Discovered: 2025-04-06
Name disclosed soon…
Logo
Discovered: 2025-04-06
Pending…
Logo
Discovered: 2025-04-06  ·  Attack est.: 2025-03-22
Still in negotiation…