{"id":4112,"date":"2025-07-01T23:20:24","date_gmt":"2025-07-01T23:20:24","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=4112"},"modified":"2025-07-01T23:20:25","modified_gmt":"2025-07-01T23:20:25","slug":"new-devman-ransomware-by-dragonforce-targets-home-windows-10-and-11-customers","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=4112","title":{"rendered":"New DEVMAN Ransomware by DragonForce Targets Home windows 10 and 11 Customers"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>A brand new ransomware variant, dubbed DEVMAN, has surfaced within the cyberthreat panorama, showcasing a fancy lineage tied to the infamous DragonForce household. <\/p>\n<p>Constructed on a basis of DragonForce and Conti codebases, DEVMAN introduces distinctive identifiers such because the .DEVMAN file extension and distinct behavioral traits, setting it aside whereas retaining core similarities with its predecessors. <\/p>\n<p>This hybrid pressure, lately analyzed in ANY.RUN\u2019s safe sandbox, targets Home windows 10 and 11 techniques, encrypting information quickly and making an attempt lateral motion by way of SMB shares. <\/p>\n<h2 class=\"wp-block-heading\"><strong>A Hybrid Menace Emerges from DragonForce Codebase<\/strong><\/h2>\n<p>Nonetheless, its deployment seems experimental, with crucial flaws like self-encrypting ransom notes undermining its effectiveness. <\/p>\n<p>Regardless of being flagged by most antivirus engines as DragonForce or Conti, deeper evaluation reveals DEVMAN\u2019s separate infrastructure, together with a Devoted Leak Website (DLS) named \u201cDevman\u2019s Place,\u201d claiming practically 40 victims primarily in Asia and Africa.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEju3vnU7DCnBwuT7vfpLaOggM0TWWGeh3TR2M9rBiewigjwbzSQy1u3RGrsMjBXw7UuHnxUL_FeGF9oG9R4FlyMDbnafY8F9GqhyphenhyphenGb1ss3CqL3bw3GGjdQO8pJT4Bkl8OhUgz9Q2mt8CkfzD85cpOR98IEiBRlwxQnVyJ_L8m4E4jiBFwtfiZpD9FtzVCc\/s16000\/Encrypted%20file%20with%20the%20.DEVMAN%20extension.webp\" alt=\"DEVMAN Ransomware\"\/><figcaption class=\"wp-element-caption\"><em>Encrypted file with the .DEVMAN extension<\/em>\u00a0<\/figcaption><\/figure>\n<\/div>\n<p>DEVMAN\u2019s conduct displays intriguing inconsistencies throughout <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/jaskago-malware-attacking-windows-and-macos\/\" target=\"_blank\" rel=\"noreferrer noopener\">working techniques<\/a> and execution environments. <\/p>\n<p>On Home windows 10, the ransomware efficiently alters desktop wallpapers to show ransom calls for, but it fails to take action on Home windows 11 for causes but to be decided. <\/p>\n<p>Its encryption course of is notably aggressive, providing three modes full, header-only, and customized permitting attackers to prioritize pace or depth of affect. <\/p>\n<h2 class=\"wp-block-heading\"><strong>Operational Challenges<\/strong><\/h2>\n<p>A placing flaw in its builder logic ends in the encryption of its personal ransom notes, rendering them unreadable and successfully severing the communication channel for cost directions. <\/p>\n<p>This crucial oversight, coupled with deterministic file renaming (e.g., ransom notes constantly renamed to \u201ce47qfsnz2trbkhnt.devman\u201d), suggests DEVMAN should still be in a testing section fairly than a cultured manufacturing risk. <\/p>\n<p>Moreover, the ransomware operates primarily offline, with no exterior command-and-control (C2) communication noticed, relying as a substitute on native SMB probing to unfold inside networks. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgok3OoIsPlxlCWCywfUcx7PhmxGPgW0vmJN-I5Sx-mK1WqSu7vh41fs8HRtSBvI0AaU9-cY3cSpJYTjGkwOd3Wkdu0VJ7dYuoTbWNbLtLRQMmMeDHoy68YvSLFA1UHQnhhXVkvLMNOZ5NpxlFZjaDVD4zUp6ky7GXvKphW4tsNuX4DQXiR38vCs6pOrTE\/s16000\/Automatic%20detection%20labels%20the%20sample%20as%20DragonForce.webp\" alt=\"DEVMAN Ransomware\"\/><figcaption class=\"wp-element-caption\"><em>Computerized detection labels the pattern as \u201cDragonForce\u201d<\/em>\u00a0<\/figcaption><\/figure>\n<\/div>\n<p>Its use of Home windows Restart Supervisor to bypass file locks and hardcoded mutexes like \u201chsfjuukjzloqu28oajh727190\u201d for execution coordination additional ties it to Conti-derived techniques, methods, and procedures (TTPs).<\/p>\n<p>The pattern additionally demonstrates rudimentary persistence and evasion mechanisms, resembling deleting registry keys post-modification and checking for Shadow Copies to inhibit system restoration. <\/p>\n<p>Whereas not groundbreaking in sophistication, these quirks present worthwhile insights into the evolving <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/category\/cyber-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">ransomware-as-a-service (RaaS) ecosystem<\/a>, the place associates customise present frameworks like DragonForce to create spinoff variants. <\/p>\n<p>DEVMAN\u2019s emergence underscores the fragmented nature of contemporary ransomware improvement, the place code reuse and misconfigurations usually blur attribution strains. <\/p>\n<p>Based on the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/any.run\/cybersecurity-blog\/devman-ransomware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Report<\/a>, Safety groups leveraging instruments like ANY.RUN\u2019s Interactive Sandbox can acquire real-time visibility into such threats, mapping behaviors, extracting indicators of compromise (IOCs), and enhancing response workflows regardless of the malware\u2019s erratic execution.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Indicators of Compromise (IOCs)<\/strong><\/h2>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th><strong>Sort<\/strong><\/th>\n<th><strong>Worth<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>MD5<\/td>\n<td>e84270afa3030b48dc9e0c53a35c65aa<\/td>\n<\/tr>\n<tr>\n<td>SHA256 (Pattern 1)<\/td>\n<td>df5ab9015833023a03f92a797e20196672c1d6525501a9f9a94a45b0904c7403<\/td>\n<\/tr>\n<tr>\n<td>SHA256 (Pattern 2)<\/td>\n<td>018494565257ef2b6a4e68f1c3e7573b87fc53bd5828c9c5127f31d37ea964f8<\/td>\n<\/tr>\n<tr>\n<td>File Identify (Mutex)<\/td>\n<td>hsfjuukjzloqu28oajh727190<\/td>\n<\/tr>\n<tr>\n<td>File Identify (Observe)<\/td>\n<td>e47qfsnz2trbkhnt.devman<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\"><strong>Discover this Information Fascinating! Observe us on\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">Google Information<\/a>,\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.linkedin.com\/company\/cyber-threat-intel\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>, and\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/The_Cyber_News\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get On the spot Updates<\/strong><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>A brand new ransomware variant, dubbed DEVMAN, has surfaced within the cyberthreat panorama, showcasing a fancy lineage tied to the infamous DragonForce household. Constructed on a basis of DragonForce and Conti codebases, DEVMAN introduces distinctive identifiers such because the .DEVMAN file extension and distinct behavioral traits, setting it aside whereas retaining core similarities with its [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":4114,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[3741,1753,500,303,342,1059],"class_list":["post-4112","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-devman","tag-dragonforce","tag-ransomware","tag-targets","tag-users","tag-windows"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/4112","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4112"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/4112\/revisions"}],"predecessor-version":[{"id":4113,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/4112\/revisions\/4113"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/4114"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4112"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4112"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4112"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-21 05:57:03 UTC -->