HackerFeeds
All ransomware groups

devman

184 tracked victims
·first seen 2023-06-07·last activity 2026-02-03

Group profile

Former RansomHub and INC Ransom affiliate.

MITRE ATT&CK TTPs

TA0001

Initial Access

  • T1078Valid Accounts

    Use of valid credentials (malharbi) to access systems.

  • T1210Exploitation of Remote Services

    Use of the MS17-010 (EternalBlue) exploit.

TA0002

Execution

  • T1059.001PowerShell

    Execution of PowerShell commands to extract files.

  • T1203Exploitation for Client Execution

    Command execution using MS17-010 via Metasploit.

TA0003

Persistence

  • T1078Valid Accounts

    Maintaining access with created administrator account.

TA0004

Privilege Escalation

  • T1068Exploitation for Privilege Escalation

    Escalation to SYSTEM privileges.

TA0005

Defense Evasion

  • T1036Masquerading

    Use of an innocuous name for the ransomware payload (iamdidy.e).

  • T1562.001Disable or Modify Tools

    No security tools detected on target systems.

TA0006

Credential Access

  • T1003OS Credential Dumping

    Implied by acquisition and use of admin credentials.

TA0007

Discovery

  • T1018Remote System Discovery

    Network mapping using CrackMapExec.

  • T1046Network Service Scanning

    Scanning IP ranges and SMB services.

  • T1082System Information Discovery

    Using tasklist and whoami to collect system info.

TA0008

Lateral Movement

  • T1021.002SMB/Windows Admin Shares

    Lateral movement through SMB confirmed by CME.

TA0009

Collection

  • T1005Data from Local System

    File extraction from local system using PowerShell.

TA0010

Exfiltration

  • T1041Exfiltration Over C2 Channel

    Downloading files like notepad.exe via smbclient.

TA0040

Impact

  • T1486Data Encrypted for Impact

    Encryption of files with .devman extension (changed at operator's request).

  • T1489Service Stop

    Halting operations and rendering systems unavailable.

  • T1490Inhibit System Recovery

    Disabling backups and system recovery.

  • T1491Defacement

    Ransom notes (ransom.txt) deployed across infected systems.

Recent victims

showing 50 of 184
DateWebsite / victimSectorCountry
2026-02-03
crystalcoastpm.com
Crystal Coast Pain Managementcrystalcoastpm.com
HealthcareUS
2026-02-02
encompass-inc.com
ENCOMPASS-INCencompass-inc.com
Financial ServicesUS
2026-01-30
woodwardoralsurgery.com
woodwardoralsurgery.comwoodwardoralsurgery.com
HealthcareSJ
2026-01-30
wjnklaw.com
wjnklaw.comwjnklaw.com
Not FoundUS
2026-01-26
consultaegis.com
consultaegis.comconsultaegis.com
Public SectorUS
2026-01-28
Z
zallc.orgz*l*c.o*g
Financial ServicesUS
2026-01-26
***vandenberg.com
***vandenberg.com***vandenberg.com
Not FoundUS
2026-01-28
**ps.net
**ps.net**ps.net
Not FoundUS
2026-01-28
tiw-group.com
tiw-group.comtiw-group.com
TechnologySJ
2026-01-28
Z
z*l*c.o*gz*l*c.o*g
Financial ServicesUS
2026-01-27
twi-group.com
twi-group.comtwi-group.com
Transportation/LogisticsUS
2026-01-26
c*n**lta**i*.com
c*n**lta**i*.comc*n**lta**i*.com
Public SectorUS
2026-01-25
cs.at
cs.atcs.at
Financial ServicesAT
2026-01-25
**.at
**.at**.at
Not FoundAT
2026-01-24
*
****cr*nem*ds.c*m****cr*nem*ds.c*m
HealthcareSJ
2026-01-24
*
***-gr*up.com
Not FoundSJ
2026-01-20
automax.com
automax.comautomax.com
Consumer ServicesIN
2026-01-20Business ServicesIN
2026-01-20
***m*sic.fi
***m*sic.fi***m*sic.fi
Not FoundFI
2026-01-20
W
www.****law.com
Financial ServicesUS
2026-01-21
***om****s-***.com
***om****s-***.com***om****s-***.com
Not FoundUS
2026-01-21
mims.com
www.mims.comwww.mims.com
HealthcareSN
2026-01-21
saundersandsaunders.com
www.saundersandsaunders.comwww.saundersandsaunders.com
Not FoundUS
2026-01-20Consumer ServicesBR
2026-01-12
klhindustries.com
klhindustries.comklhindustries.com
ManufacturingUS
2026-01-12
pronaca.com
pronaca.compronaca.com
Agriculture and Food ProductionSJ
2026-01-11
consigaz.com.br
consigaz.com.brconsigaz.com.br
EnergyBR
2026-01-11
sealbeachca.gov
sealbeachca.govsealbeachca.gov
Public SectorUS
2026-01-11
sealbeachpd.com
sealbeachpd.comsealbeachpd.com
Public SectorUS
2026-01-11
******medical.com
******m*di*al.com******medical.com
HealthcareUS
2026-01-12
****t*lc*a*tpm.com
****t*lc*a*tpm.com****t*lc*a*tpm.com
HealthcareSJ
2026-01-12
s***p.com
s***p.coms***p.com
Business ServicesSJ
2025-12-25
intonu.com
Intonu.comIntonu.com
Financial ServicesUS
2025-12-27
oppor**nity*****.org
oppor**nity*****.orgoppor**nity*****.org
HealthcareUS
2025-12-27
J
Jennings SDJennings SD
Financial ServicesUS
2025-12-28
sharinc.org
sharinc.orgsharinc.org
Business ServicesUS
2025-12-25
kavi.fi
kavi.fikavi.fi
Business ServicesFI
2025-12-25
i**o**.us
i**o**.usi**o**.us
TechnologyUS
2025-12-25
***ind***es.com
***ind***es.com***ind***es.com
Business ServicesUS
2025-12-18
davila.cl
Clínica Dáviladavila.cl
HealthcareCL
2025-12-22
k*v*.fi
k*v*.fik*v*.fi
Business ServicesFI
2025-12-19
transrocamar.com
transrocamar.comtransrocamar.com
Financial ServicesES
2025-12-22
bhhpa.org.uk
British Holiday & Home Parks Association Ltdwww.bhhpa.org.uk
Hospitality and TourismUK
2025-12-19
C
consult*****.c**consult*****.c**
Financial ServicesUS
2025-12-19TechnologyCN
2025-12-19
****s*oc****.com
****s*oc****.com****s*oc****.com
Financial ServicesES
2025-12-17
culinaryjetconcierge.com
Culinary Jet Conciergewww.culinaryjetconcierge.com
Hospitality and TourismFR
2025-12-16
beausejourco-op.crs
beausejourco-op.crsbeausejourco-op.crs
Agriculture and Food ProductionCA
2025-12-18
d*v***.cl
d*v***.cld*v***.cl
HealthcareCL
2025-12-16Financial ServicesCA