
ANY.RUN Releases Technical Analysis of DEVMAN Ransomware Built on DragonForce RaaS
DUBAI, DUBAI, UNITED ARAB EMIRATES, July 1, 2025 /EINPresswire.com/ -- ANY.RUN, a trusted provider of cybersecurity solutions, has published a new technical analysis revealing a ransomware variant that blends traits of DragonForce and Conti families with indicators of a newer actor known as DEVMAN.
๐๐๐๐๐๐: ๐ ๐๐๐ฐ ๐๐ก๐ซ๐๐๐ญ ๐๐๐ญ๐จ๐ซ ๐๐๐ซ๐ ๐๐ญ๐ข๐ง๐ ๐๐ง๐ญ๐๐ซ๐ฉ๐ซ๐ข๐ฌ๐๐ฌ
DEVMAN is a relatively new actor has recently emerged under this name, featuring its own Dedicated Leak Site (DLS) called Devmanโs Place, a separate infrastructure, and nearly 40 claimed victims, primarily in Asia and Africa, with occasional incidents in Latin America and Europe.
๐๐๐๐๐๐ ๐๐๐ง๐ฌ๐จ๐ฆ๐ฐ๐๐ซ๐: ๐ ๐๐ฒ๐๐ซ๐ข๐ ๐๐ก๐ซ๐๐๐ญ
The analyzed sample, initially labeled as DragonForce by antivirus engines, was revealed to be a lightly modified build. It appends the โ.DEVMANโ extension to encrypted files, scrambles filenames using a deterministic function, and, due to a builder flaw, encrypts its own ransom notes before victims can read them.
๐๐๐ฒ ๐ ๐ข๐ง๐๐ข๐ง๐ ๐ฌ ๐จ๐ ๐ญ๐ก๐ ๐๐๐๐๐๐ ๐๐ง๐๐ฅ๐ฒ๐ฌ๐ข๐ฌ ๐๐ง๐๐ฅ๐ฎ๐๐:
ยท ๐๐ผ๐ฐ๐ฎ๐น ๐ฒ๐ ๐ฒ๐ฐ๐๐๐ถ๐ผ๐ป: No external C2 traffic was detected; all behavior is confined to the local system.
ยท ๐ฆ๐ ๐ ๐ฝ๐ฟ๐ผ๐ฏ๐ถ๐ป๐ด: The sample attempts to access hardcoded SMB shares such as ADMIN$.
ยท ๐๐ผ๐ป๐๐ถ-๐๐๐๐น๐ฒ ๐ฝ๐ฒ๐ฟ๐๐ถ๐๐๐ฒ๐ป๐ฐ๐ฒ: The use of mutexes and the Windows Restart Manager mirrors tactics from Conti and DragonForce campaigns.
To explore the full technical breakdown and see how DEVMAN behaves inside the sandbox, visit the ANY.RUN blog.
๐๐๐จ๐ฎ๐ญ ๐๐๐.๐๐๐
ANY.RUN offers a comprehensive suite of cybersecurity solutions, including their Interactive Sandbox and advanced Threat Intelligence services. Trusted by over 15,000 companies worldwide, ANY.RUN enables dynamic malware analysis across Windows, Linux, and Android systems.
In addition to sandboxing, ANY.RUN provides Threat Intelligence Lookup, Feeds, and YARA Search, helping security teams detect, investigate, and respond to threats with greater speed and accuracy.
The ANY.RUN team
ANYRUN FZCO
+1 657-366-5050
email us here
Visit us on social media:
LinkedIn
YouTube
X

Distribution channels: Banking, Finance & Investment Industry, Business & Economy, Companies, IT Industry, Technology
Legal Disclaimer:
EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.
Submit your press release