DevMan ransomware locker capability update for Windows, ESXi, and Linux
Malware Activity
Summary
Hide ▲
Show ▼
The DevMan ransomware locker now supports payload builds for Windows, ESXi, and Linux, expanding the operation's reach across server and workstation environments. Analysis of the Windows build shows features for privilege checks, process and service termination, recovery inhibition, event log clearing, lateral movement, and multi-threaded encryption, all of which increase the impact of an infection. The locker also uses ChaCha20-Poly1305 and can self-delete, making remediation harder after deployment.
Related Happenings
DevMan-Funky Mantis ecosystem shift changes threat-actor operations
Threat Actor Meta
H score46
First: 25.07.2026 12:53
Last: 25.07.2026 12:53
Sources 1
How related:
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims.
About this happening:
DevMan has consolidated its RaaS affiliate portal, tightening control over payload creation, victim handling, and payouts across its criminal service network. PRODAFT...
DevMan-Funky Mantis ecosystem shift changes threat-actor operations
Threat Actor MetaHow related: The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims.
About this happening: DevMan has consolidated its RaaS affiliate portal, tightening control over payload creation, victim handling, and payouts across its criminal service network. PRODAFT...
Vect ransomware flawed ChaCha20 implementation destroys large files
Technical Analysis
H score4
First: 29.04.2026 13:45
Last: 29.04.2026 13:45
Sources 1
About this happening:
Vect 2.0 ransomware was shown to use raw ChaCha20-IETF (RFC 8439) without authentication, causing files above 128 KB to be permanently destroyed across Windows, Linu...
Vect ransomware flawed ChaCha20 implementation destroys large files
Technical AnalysisAbout this happening: Vect 2.0 ransomware was shown to use raw ChaCha20-IETF (RFC 8439) without authentication, causing files above 128 KB to be permanently destroyed across Windows, Linu...
VECT 2.0 ransomware-branded file destruction malware
Malware Activity
H score4
First: 28.04.2026 17:01
Last: 28.04.2026 17:01
Sources 1
About this happening:
The VECT 2.0 malware now behaves like a wiper rather than recoverable ransomware, permanently destroying large files and raising the stakes for victims. The destructive fl...
VECT 2.0 ransomware-branded file destruction malware
Malware ActivityAbout this happening: The VECT 2.0 malware now behaves like a wiper rather than recoverable ransomware, permanently destroying large files and raising the stakes for victims. The destructive fl...
Medusa ransomware post-compromise deployment
Malware Activity
H score48
First: 07.04.2026 09:35
Last: 07.04.2026 09:35
Sources 1
About this happening:
Medusa ransomware is being deployed rapidly after initial access, turning intrusions into fast-moving extortion events and shrinking defenders' response time. The malware acti...
Medusa ransomware post-compromise deployment
Malware ActivityAbout this happening: Medusa ransomware is being deployed rapidly after initial access, turning intrusions into fast-moving extortion events and shrinking defenders' response time. The malware acti...
Remcos RAT variant with real-time surveillance and evasion
Malware Activity
H score28
First: 19.02.2026 18:30
Last: 19.02.2026 18:30
Sources 1
About this happening:
A newly observed Remcos RAT variant now enables real-time surveillance on compromised Windows systems, increasing the risk of immediate webcam monitoring and liv...
Remcos RAT variant with real-time surveillance and evasion
Malware ActivityAbout this happening: A newly observed Remcos RAT variant now enables real-time surveillance on compromised Windows systems, increasing the risk of immediate webcam monitoring and liv...
Timeline
-
25.07.2026 12:53 2 articles · 2h ago
DevMan portal expands locker support to Windows, ESXi, and Linux
Technical Analysis UpdateDevMan's latest portal version lets affiliates create a locker for Windows, ESXi, or Linux, and the Windows build includes privilege checking, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, optional self-deletion, and ChaCha20-Poly1305 encryption.
Show sources
- DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts — thehackernews.com — 25.07.2026 12:53
- DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts — thehackernews.com — 25.07.2026 12:53