// THREAT ACTOR
DEVMAN_
DormantDEVMAN is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of DEVMAN — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Victims by year
- 2025 49
Leak site mirrors
1 mirror tracked, 0 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
qljmlmp4psnn3wqskkf3alqquatymo6hntficb4rhq5n76kuogcv7zyd.onionDevman's Place snapshot · 2025-06-16 02:17
Recent victims
The 50 most recent victims claimed by DEVMAN. Total in the index: 49.
| Date listed | Victim | Description |
|---|---|---|
| 2025-06-07 | NSSF KENYA(negotiation started) /nssf.zip - first samle /nssfwriteup.html - writeup | |
| 2025-06-02 | DHL THAILAND | |
| 2025-05-31 | lantro.com | |
| 2025-05-26 | dmbarone.com | |
| 2025-05-26 | Gobierno del Estado de Colima | |
| 2025-05-25 | SAVE THIS PGP MESSAGE | |
| 2025-05-25 | www.nijar.es | |
| 2025-05-23 | www.paragonradiology.com | |
| 2025-05-23 | netstar.co.za | |
| 2025-05-23 | NSSF KENYA(negotiation started) | |
| 2025-05-19 | NSSF KENYA | |
| 2025-05-19 | TBD KOREA | |
| 2025-05-19 | TBD HONK KONG | |
| 2025-05-19 | TBD GREECE | |
| 2025-05-19 | TOHO-CO | |
| 2025-05-19 | TBD KENYA | |
| 2025-05-19 | piriou.vn | |
| 2025-05-11 | tvgoiania.com.br | |
| 2025-05-10 | Pienaar Brothers (DevMan Ransomware) | |
| 2025-05-10 | Victim from Japan | |
| 2025-05-09 | dailynews.co.th (DevMan Ransomware) | |
| 2025-05-07 | https://www.gmanetwork.com/news/(DevMan Ransomware) | |
| 2025-05-05 | https://pestbusters.com.sg/ | |
| 2025-05-02 | smvthailand.com | |
| 2025-05-01 | Chinese Healthcare Organisation (TBD) | |
| 2025-05-01 | Singapour Factory | |
| 2025-05-01 | South African IT firm (TBD) | |
| 2025-05-01 | South African Hr company (TBD) | |
| 2025-05-01 | dovesit.co.za (Ransomhub) | |
| 2025-04-25 | EU victim (To be discoled) | |
| 2025-04-24 | China Harbour (s) Engeneiring Company (Dragon Force Attack) FILE SAMPLE 1 avaliable /CHEC/ | |
| 2025-04-20 | Premier Meats South Africa(Only files where exflitrated) | |
| 2025-04-20 | Feel Four (QILIN Attack) | |
| 2025-04-20 | Singapour Victim (To be discoled) | |
| 2025-04-20 | Honk Kong Victim (To be discoled) | |
| 2025-04-20 | China Harbour (s) Engeneiring Company (Dragon Force Attack) | |
| 2025-04-13 | FEELFOUR (QILIN) | |
| 2025-04-12 | Company located in catalonia ES (Name - soon) | |
| 2025-04-12 | Med institute (Name - soon) | |
| 2025-04-12 | Prvate hospital (Name - soon) | |
| 2025-04-12 | Bangkok Electronics Co., Ltd (QILIN) | |
| 2025-04-07 | Tawasol (APOS Attack) | |
| 2025-04-07 | Texas Construction Firm(QILIN) | |
| 2025-04-07 | Optimax Technology(QILIN) | |
| 2025-04-07 | Doumen.fr(QILIN) | |
| 2025-04-06 | Dubai Company | |
| 2025-04-06 | Texas Construction Firm | |
| 2025-04-06 | Optimax Technology | |
| 2025-04-06 | doumen.fr |