Listen to this Post

The Rise of a New Ransomware Variant
Cybersecurity researchers have identified a dangerous new ransomware strain known as DEVMAN, which has begun targeting Windows 10 and 11 systems. Unlike earlier threats, DEVMAN exhibits a combination of reused code and new, unpredictable behaviors. It is believed to be a descendant of the DragonForce ransomware family, itself derived from the notorious Conti framework. This connection places DEVMAN within a dangerous legacy of Ransomware-as-a-Service (RaaS), but with enough unique traits to make it a fresh challenge for cybersecurity professionals.
This latest malware variant reveals not just how attackers are recycling effective techniques but also how rapid evolution and customization can introduce both new capabilities and critical flaws. DEVMAN’s odd behavior, especially the self-encryption of its own ransom notes, sets it apart technically, even as it follows traditional ransomware tactics like file encryption, lateral movement via SMB probing, and desktop wallpaper changes on infected machines. Its ability to operate offline, its fragmented lineage, and its own dedicated leak site (DLS) suggest that this is no mere copycat but an active and evolving cyber threat that’s already claiming victims—particularly in Asia and Africa.
A Deep Dive into DEVMAN’s Operations
Code Reuse Meets Unique Signature
DEVMAN was initially flagged by AV engines as DragonForce or Conti, but closer inspection uncovered distinct differences. The malware appends a .DEVMAN extension to encrypted files and features unique code strings that show branding and infrastructure separate from its predecessors. It likely originated from a ransomware builder designed for DragonForce affiliates but has been modified for independent deployment.
Ransom Note Chaos
One of DEVMAN’s most notable missteps is its tendency to encrypt its own ransom notes due to a flaw in its builder. Instead of leaving clear instructions for victims, the malware renames the ransom note files to a random-looking string such as e47qfsnz2trbkhnt.devman. This hinders communication between victims and attackers and ironically serves as a telltale sign for cybersecurity teams.
Inconsistent Behavior Across OS Versions
While DEVMAN successfully modifies desktop wallpapers on Windows 10, this feature fails to function on Windows 11, indicating incomplete compatibility or testing. This inconsistency further supports the theory that DEVMAN is still under active development, possibly rushed into deployment.
Offline and Stealthy
DEVMAN doesn’t rely on traditional command-and-control (C2) communication. Instead, it operates primarily offline, searching for SMB shares to spread across networks. Its encryption engine includes three modes—full, header-only, and custom—allowing attackers to prioritize speed or thoroughness based on target environment.
Persistence and Evasion Tactics
Borrowing tricks from Conti, DEVMAN uses the Windows Restart Manager to unlock active files and ensure encryption. It briefly writes and deletes registry entries, aiming to avoid detection during forensic analysis. Mutexes are deployed to avoid duplicate instances during execution, enhancing its stealth.
Growing Footprint and Autonomy
Though heavily based on DragonForce, DEVMAN has begun to diverge from that codebase. The ransomware operators now maintain a Dedicated Leak Site to pressure victims into payment. Nearly 40 victims have been confirmed, mostly across Asia and Africa, suggesting targeted regional campaigns.
What Undercode Say:
Affiliate Chaos in the RaaS Ecosystem
DEVMAN reflects a broader trend in cybercrime—the decentralization of ransomware development. What once were tightly controlled ransomware gangs have now fragmented into affiliate-based operations. This means more attackers with access to powerful codebases, often modified hastily and without the rigorous testing seen in earlier strains.
The Power and Pitfalls of DIY Malware Builders
By leveraging toolkits like those used in DragonForce, even relatively unsophisticated actors can deploy complex ransomware. However, DEVMAN’s ransom note encryption bug highlights the risks of automated builder tools—minor errors can break key functionality, impacting ransom collection and attacker reputation.
Offline Operation: A Strategic Advantage
The
Encryption Tactics with a Purpose
The ability to choose between full, header-only, or custom encryption allows attackers to adapt to different file structures and system performance limitations. This modularity shows a higher level of thought put into the malware’s design, despite its other shortcomings.
Unique Indicators as a Double-Edged Sword
Ironically, DEVMAN’s uniqueness, particularly its ransom note naming bug, becomes its own Indicator of Compromise (IOC). Cybersecurity teams can leverage these anomalies to detect infections early and initiate remediation before the ransomware causes irreparable damage.
A Work-in-Progress or a Smokescreen?
The inconsistency in behavior across OS versions and clumsy implementation of some features suggest that DEVMAN might be an early prototype or a decoy campaign meant to test certain behaviors before a larger rollout. Either way, it’s a live threat and part of a wider ecosystem where attackers are rapidly deploying and testing new iterations in the wild.
Regional Focus Raises Alarm Bells
Its concentration of victims in Asia and Africa hints at either intentional regional targeting or a reflection of weaker cyber defenses in certain countries. These attacks are not random; they’re part of a strategic shift by ransomware groups looking to exploit gaps in detection, response, and international cybersecurity coordination.
DragonForce’s Shadow Still Looms
Despite its divergence, DEVMAN’s core DNA is still tied to DragonForce, and by extension, Conti. This continued reuse of legacy ransomware architectures means defenders can study old threats to prepare for new ones. However, attackers also learn from each other, evolving fast and repackaging vulnerabilities faster than traditional security patches can catch up.
🔍 Fact Checker Results:
✅ DEVMAN appends .DEVMAN to encrypted files and encrypts its own ransom notes due to a builder flaw
✅ It originates from the DragonForce lineage but exhibits unique behaviors and infrastructure
✅ Nearly 40 victims are confirmed, with a concentration in Asia and Africa 🌍
📊 Prediction:
In the coming months, DEVMAN is likely to evolve rapidly. Expect updated variants with fixed bugs and broader targeting, including European and North American enterprises. Given its offline tactics and modular encryption, DEVMAN could become a favored choice among low-skill affiliates using RaaS platforms. Cybersecurity teams should monitor for its unique indicators and prepare for similar hybrids emerging from the shadows of legacy ransomware codebases. 🔐🧠
References:
Reported By: cyberpress.org
Extra Source Hub:
https://stackoverflow.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2




