devman
Former RansomHub and INC Ransom affiliate.
Devman is a cybercrime actor known for RDP-based ransomware operations, affiliated with RansomHub and INC Ransom.
Devman (also known as Devman 2.0) is a cybercrime actor, formerly affiliated with the RansomHub and INC Ransom groups. They primarily target organizations across various sectors. Their typical TTPs involve exploiting Remote Desktop Protocol (RDP) weaknesses for initial access, stealing data, and deploying ransomware. Defenders should focus on strengthening RDP security, enforcing multi-factor authentication, and monitoring for unusual lateral movement activity within the network.
Former RansomHub and INC Ransom affiliate.
Devman typically gains initial access by exploiting Remote Desktop Protocol (RDP) weaknesses.
Defenders should strengthen RDP security, enforce multi-factor authentication (MFA), and monitor for unusual lateral movement activity within the network.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.