Find notable cyber news and cases, enriched with sources, timelines, and signals.

DevMan ransomware locker capability update for Windows, ESXi, and Linux

Malware Activity
First reported
Last updated
Happening score
H score 38
1 unique sources, 1 articles

Summary

Hide ▲

The DevMan ransomware locker now supports payload builds for Windows, ESXi, and Linux, expanding the operation's reach across server and workstation environments. Analysis of the Windows build shows features for privilege checks, process and service termination, recovery inhibition, event log clearing, lateral movement, and multi-threaded encryption, all of which increase the impact of an infection. The locker also uses ChaCha20-Poly1305 and can self-delete, making remediation harder after deployment.

Related Happenings

DevMan-Funky Mantis ecosystem shift changes threat-actor operations

Threat Actor Meta
H score46 First: 25.07.2026 12:53 Last: 25.07.2026 12:53 Sources 1

How related: The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims.

About this happening: DevMan has consolidated its RaaS affiliate portal, tightening control over payload creation, victim handling, and payouts across its criminal service network. PRODAFT...

Vect ransomware flawed ChaCha20 implementation destroys large files

Technical Analysis
H score4 First: 29.04.2026 13:45 Last: 29.04.2026 13:45 Sources 1

About this happening: Vect 2.0 ransomware was shown to use raw ChaCha20-IETF (RFC 8439) without authentication, causing files above 128 KB to be permanently destroyed across Windows, Linu...

VECT 2.0 ransomware-branded file destruction malware

Malware Activity
H score4 First: 28.04.2026 17:01 Last: 28.04.2026 17:01 Sources 1

About this happening: The VECT 2.0 malware now behaves like a wiper rather than recoverable ransomware, permanently destroying large files and raising the stakes for victims. The destructive fl...

Medusa ransomware post-compromise deployment

Malware Activity
H score48 First: 07.04.2026 09:35 Last: 07.04.2026 09:35 Sources 1

About this happening: Medusa ransomware is being deployed rapidly after initial access, turning intrusions into fast-moving extortion events and shrinking defenders' response time. The malware acti...

Remcos RAT variant with real-time surveillance and evasion

Malware Activity
H score28 First: 19.02.2026 18:30 Last: 19.02.2026 18:30 Sources 1

About this happening: A newly observed Remcos RAT variant now enables real-time surveillance on compromised Windows systems, increasing the risk of immediate webcam monitoring and liv...

Timeline

  1. 25.07.2026 12:53 2 articles · 2h ago

    DevMan portal expands locker support to Windows, ESXi, and Linux

    Technical Analysis Update

    DevMan's latest portal version lets affiliates create a locker for Windows, ESXi, or Linux, and the Windows build includes privilege checking, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, optional self-deletion, and ChaCha20-Poly1305 encryption.

    Show sources