Executive Summary
In April 2025, the DevMan ransomware-as-a-service (RaaS) operation emerged, initially affiliating with groups like Qilin, DragonForce, Apos, and RansomHub. By July 2025, DevMan transitioned into an independent RaaS platform, offering affiliates a centralized web portal for payload generation, financial management, victim communication, and operational coordination. This portal streamlined the ransomware deployment process, integrating access brokerage with ransomware execution, and imposed strict completion timelines on affiliates. The operation has claimed 184 victims to date, with nearly 50 located in the U.S., targeting sectors such as technology, healthcare, financial services, professional services, and government.
The evolution of DevMan underscores a significant shift in the ransomware landscape, where threat actors are developing sophisticated, centralized platforms to enhance operational efficiency and scalability. This trend highlights the increasing professionalization of cybercriminal enterprises and the need for organizations to bolster their cybersecurity defenses against such organized threats.
Why This Matters Now
The emergence of centralized RaaS platforms like DevMan signifies a growing trend in the professionalization and efficiency of cybercriminal operations, posing heightened risks to organizations across various sectors. Immediate attention to advanced cybersecurity measures is crucial to mitigate these evolving threats.
Attack Path Analysis
The attack began with the DevMan RaaS portal providing affiliates with tools to generate ransomware payloads, leading to initial compromises through phishing or exploitation of vulnerabilities. Affiliates then escalated privileges within the compromised systems to gain administrative access. Subsequently, they moved laterally across networks to identify and access critical assets. Command and control channels were established to manage the deployment and execution of ransomware. Data was exfiltrated to pressure victims into paying ransoms. Finally, the ransomware encrypted data and disrupted operations, culminating in financial demands from the attackers.
Kill Chain Progression
Initial Compromise
Description
Affiliates utilized the DevMan RaaS portal to create ransomware payloads, which were delivered to victims via phishing emails or by exploiting known vulnerabilities.
MITRE ATT&CK® Techniques
Compromise Infrastructure
Valid Accounts
Command and Scripting Interpreter
Data Encrypted for Impact
Exfiltration Over Web Service
Application Layer Protocol
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure the security of payment applications
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Data
Control ID: Pillar 3
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Health Care / Life Sciences
DevMan RaaS threatens patient data with centralized payload builds, exploiting lateral movement gaps and encryption weaknesses in HIPAA-regulated environments.
Financial Services
Banking institutions face ransomware attacks through unencrypted traffic and inadequate east-west segmentation, compromising PCI compliance and customer financial data.
Government Administration
Government agencies vulnerable to DevMan affiliate operations targeting critical infrastructure through zero trust segmentation failures and multicloud visibility gaps.
Information Technology/IT
IT service providers exposed to ransomware-as-a-service attacks exploiting Kubernetes security weaknesses and inadequate egress filtering for client protection.
Sources
- DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payoutshttps://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.htmlVerified
- ANY.RUN Releases Technical Analysis of DEVMAN Ransomware Built on DragonForce RaaShttps://www.latamtechnologyreporter.com/article/827298083-any-run-releases-technical-analysis-of-devman-ransomware-built-on-dragonforce-raasVerified
- NHS GP software supplier hit by cyber attackhttps://www.digitalhealth.net/2025/12/nhs-gp-software-supplier-hit-by-cyber-attack/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Implementing Aviatrix Zero Trust CNSF would likely constrain the attacker's ability to move laterally and exfiltrate data, thereby reducing the overall impact of the incident.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial access may still occur, the attacker's ability to exploit vulnerabilities would likely be constrained, reducing the scope of the compromise.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely be constrained, reducing their control over the compromised systems.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally would likely be constrained, reducing their access to critical assets.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels would likely be constrained, reducing their ability to manage ransomware deployment.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data would likely be constrained, reducing the risk of data loss.
The attacker's ability to disrupt operations would likely be constrained, reducing the overall impact of the ransomware.
Impact at a Glance
Affected Business Functions
- Software Development
- Customer Support
- Financial Transactions
- Affiliate Management
Estimated downtime: 14 days
Estimated loss: $500,000
Confidential affiliate information, victim data, and financial records
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Enforce Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing data exfiltration.
- • Deploy Inline IPS (Suricata) to detect and block known exploit patterns and malicious payloads.
- • Utilize Multicloud Visibility & Control to gain comprehensive insights into network traffic and detect anomalies.
- • Apply Threat Detection & Anomaly Response mechanisms to identify and respond to suspicious activities promptly.



