Genera un perfil del actor con IA (defensivo) cuando lo pidas.
Para detección/bloqueo en tu EDR/SIEM. Fuente: ransomware.live.
Firma de detección defensiva para este grupo (úsala en tu EDR/SIEM). Fuente: ransomware.live.
/*
devman ransomware
*/
rule devman_Ransomnote
{
meta:
author = "ransomware.live"
family = "ransomware.devman"
description = "Detects devman ransomware ransom note or artifact"
date = "2026-05-04"
severity = 7
score = 70
strings:
$name1 = "devman" ascii nocase
$name2 = "DEVMAN" ascii
$onion = "devman.onion" ascii nocase
condition:
any of them
}
██████╗ ███████╗██╗ ██╗███╗ ███╗ █████╗ ███╗ ██╗ ██████╗ ██╗ ██╔══██╗██╔════╝██║ ██║████╗ ████║██╔══██╗████╗ ██║ ╚════██╗ ███║ ██║ ██║█████╗ ██║ ██║██╔████╔██║███████║██╔██╗ ██║ █████╔╝ ╚██║ ██║ ██║██╔══╝ ╚██╗ ██╔╝██║╚██╔╝██║██╔══██║██║╚██╗██║ ██╔═══╝ ██║ ██████╔╝███████╗ ╚████╔╝ ██║ ╚═╝ ██║██║ ██║██║ ╚████║ ███████╗██╗██║ ╚═════╝ ╚══════╝ ╚═══╝ ╚═╝ ╚═╝╚═╝ ╚═╝╚═╝ ╚═══╝ ╚══════╝╚═╝╚═╝ ////////////////////////////////////////////////////////////////////////////// ///ENGLISH VERSION/////////////////////////////////////////////////////////// //////////////////////////////////////////////////////////////////////////// Dear, management and employees. We are the devman collective, and we are here to deliver some bad news. All of your files have been encrypted with a unbreakable encryption algorithm. However, this is not the only bad news for you. Around 100gb of your sensitive data,have been exfiltrated to our secure servers. What does that mean for you? It means that if you do not cooperate with us, not only will you lose access to your files, All of that sensitive data will be published online, causing irreparable damage to your reputation and potentially leading to legal consequences. The only way to decrypt your files, and to prevent the data leak is to cooperate with us, and get the decryption tool and unique key. What will happen if you do not cooperate with us? 1. Your files will remain encrypted forever. 2. Your sensitive data will be published online, and sent to your clients. 3. There is a high chance that you will face legal consequences for failing to protect your clients data, and violating data protection laws. How to cooperate with us? To obtain the decryption tool, you need to: 1. Contact us at: [redactado] 2. Send your unique ID: [snip] 3. Receive a sample decryption of up to 4 files, and the file listing of exfiltrated data 4. We will provide payment instructions 5. After payment, you will receive decryption tool and unique key WARNING: - Do not modify encrypted files - Do not use third party software to restore files - Do not reinstall system If you violate these rules, your files may be permanently damaged. Unique ID: [snip] Backup contact ([redactado] [redactado]
[AI generated] Tvgoiania is a media and news company based in Goiânia, Brazil. It provides a platform for local news, events, and updates significant to the Goiania area. The company offers a variety of media content in the form of live shows, news broadcasts, publications, and web content. Tvgoiania operates primarily in Portuguese language.
[AI generated] Consigaz is a Brazilian company that specializes in the distribution of Liquefied Petroleum Gas (LPG) for both industrial and residential use. They offer services such as cooking gas delivery and installation of gas systems for businesses. The company is committed to safety and environmental responsibility, using advanced technology for efficient gas handling and distribution. Consigaz operates across several Brazilian states.
| Organización | País | Sector | Grupo | Descubierta |
|---|---|---|---|---|
| Tvgoiania | BR | Consumer Services | — | 20 ene 2026 |
| consigaz.com.br | BR | Energy | — | 12 ene 2026 |
| Clínica Dávila | CL | Healthcare | — | 22 dic 2025 |
| d*v***.cl | CL | Healthcare | — | 18 dic 2025 |
| CANCER | BR | Financial Services | — | 14 dic 2025 |
| C*NC*R | BR | Financial Services | — | 11 dic 2025 |
| future.com.bo | BO | Not Found | — | 19 nov 2025 |
| juntalocal.cdmx.gob.mx | MX | Public Sector | — | 1 nov 2025 |
| EMBASY OF BOLIVIA DC | BO | Public Sector | — | 15 oct 2025 |
| ruff.com.br | BR | Not Found | — | 4 ago 2025 |
| Gobierno del Estado de Colima | MX | Public Sector | — | 26 may 2025 |
| tvgoiania.com.br | BR | Telecommunication | — | 11 may 2025 |
Las direcciones de los sitios de filtración (.onion) se conocen pero no se publican ni se enlazan. Solo se muestran metadatos públicos. ética
Patients' full records, HIV test results, IDs. Throughout a long waiting period, and despite a vast number of phone calls and emails sent by our team to the hospital, we have seen no action from the clinic to resolve the issue - knowing that the HIV tests could potentially change the lives of people whose relatives, friends, and workplaces will...
Patients full records, HIV tests results, ID's
Financial data, clients data
Financial data, clients data