216.73.216.226

DEVMAN Ransomware: Analysis of New DragonForce Variant

· Published 02/07/2025 07:14 · Modified 02/07/2025 07:46

Export JSON

Essential information

Published
02/07/2025 07:14
Modified
02/07/2025 07:46
Tags
2025-07-02 blacklock conti devman dragonforce mamona raas ransomware
Related entities
2 observables, 1 intrusion sets (apt), 9 techniques (mitre), 5 malware, 2 others

Description

A new strain resembling but with unique traits has emerged, possibly connected to an entity called . The sample reuses code but adds its own elements, including the . file extension. Attribution is unclear, as the ransom note is identical to 's. The malware operates offline, probes for SMB connections, and uses three encryption modes. It exhibits different behaviors on Windows 10 and 11, particularly in changing wallpapers. The encrypts its own ransom notes, likely due to a builder flaw. claims to have stopped using months ago, suggesting this may be an experimental or outdated build.

External references