Saturday, August 29, 2026

New DEVMAN Ransomware by DragonForce Targets Windows 10 and 11 Users

A new ransomware variant, dubbed DEVMAN, has surfaced in the cyberthreat landscape, showcasing a complex lineage tied to the notorious DragonForce family.

Built on a foundation of DragonForce and Conti codebases, DEVMAN introduces unique identifiers such as the .DEVMAN file extension and distinct behavioral traits, setting it apart while retaining core similarities with its predecessors.

This hybrid strain, recently analyzed in ANY.RUN’s secure sandbox, targets Windows 10 and 11 systems, encrypting files rapidly and attempting lateral movement via SMB shares.

A Hybrid Threat Emerges from DragonForce Codebase

However, its deployment appears experimental, with critical flaws like self-encrypting ransom notes undermining its effectiveness.

Despite being flagged by most antivirus engines as DragonForce or Conti, deeper analysis reveals DEVMAN’s separate infrastructure, including a Dedicated Leak Site (DLS) named “Devman’s Place,” claiming nearly 40 victims primarily in Asia and Africa.

DEVMAN Ransomware
Encrypted file with the .DEVMAN extension 

DEVMAN’s behavior exhibits intriguing inconsistencies across operating systems and execution environments.

On Windows 10, the ransomware successfully alters desktop wallpapers to display ransom demands, yet it fails to do so on Windows 11 for reasons yet to be determined.

Its encryption process is notably aggressive, offering three modes full, header-only, and custom allowing attackers to prioritize speed or depth of impact.

Operational Challenges

A striking flaw in its builder logic results in the encryption of its own ransom notes, rendering them unreadable and effectively severing the communication channel for payment instructions.

This critical oversight, coupled with deterministic file renaming (e.g., ransom notes consistently renamed to “e47qfsnz2trbkhnt.devman”), suggests DEVMAN may still be in a testing phase rather than a polished production threat.

Additionally, the ransomware operates primarily offline, with no external command-and-control (C2) communication observed, relying instead on local SMB probing to spread within networks.

DEVMAN Ransomware
Automatic detection labels the sample as “DragonForce” 

Its use of Windows Restart Manager to bypass file locks and hardcoded mutexes like “hsfjuukjzloqu28oajh727190” for execution coordination further ties it to Conti-derived tactics, techniques, and procedures (TTPs).

The sample also demonstrates rudimentary persistence and evasion mechanisms, such as deleting registry keys post-modification and checking for Shadow Copies to inhibit system recovery.

While not groundbreaking in sophistication, these quirks provide valuable insights into the evolving ransomware-as-a-service (RaaS) ecosystem, where affiliates customize existing frameworks like DragonForce to create spinoff variants.

DEVMAN’s emergence underscores the fragmented nature of modern ransomware development, where code reuse and misconfigurations often blur attribution lines.

According to the Report, Security teams leveraging tools like ANY.RUN’s Interactive Sandbox can gain real-time visibility into such threats, mapping behaviors, extracting indicators of compromise (IOCs), and enhancing response workflows despite the malware’s erratic execution.

Indicators of Compromise (IOCs)

TypeValue
MD5e84270afa3030b48dc9e0c53a35c65aa
SHA256 (Sample 1)df5ab9015833023a03f92a797e20196672c1d6525501a9f9a94a45b0904c7403
SHA256 (Sample 2)018494565257ef2b6a4e68f1c3e7573b87fc53bd5828c9c5127f31d37ea964f8
File Name (Mutex)hsfjuukjzloqu28oajh727190
File Name (Note)e47qfsnz2trbkhnt.devman

Find this News Interesting! Follow us on Google NewsLinkedIn, and X to Get Instant Updates

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Hackers Compromise TanStack Query npm Package to Steal Developer Credentials

A supply-chain worm has compromised multiple releases of @7nohe/openapi-react-query-codegen,...

Critical Gogs Flaw Enables Remote Code Execution Through Path Traversal

A critical vulnerability in Gogs, the self-hosted Git service,...

Hackers Use Fake Cloudflare CAPTCHA to Deploy TerminalFix Reverse Tunnel

A newly documented TerminalFix campaign is using fake Cloudflare...

Chinese Hackers Deploy PackClient RAT via Tax-Themed Phishing Attacks to Steal Data

A Chinese-speaking threat actor tracked as TA4922 is deploying...

Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against AI Infrastructure

Attackers are increasingly treating AI infrastructure as a high-value...

700 OpenAI Agents Coordinate Attack on Hugging Face and Gain Remote Code Execution

OpenAI’s ExploitGym evaluation environment reportedly became the site of...

Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit

A newly analyzed phishing operation is using server-side polymorphism...

Critical WordPress Plugin Flaw Allows Unauthenticated Administrator Account Takeover

A critical authentication bypass vulnerability has been identified in...

Related Articles

Recent News