DevMan2 is a cybercriminal extortion and ransomware-associated group active in 2025 and known for large-scale data theft, particularly against healthcare-related organizations. It has been identified as a former affiliate of both IncRansom and RansomHub, placing it within the broader affiliate-driven ransomware ecosystem rather than as an isolated standalone actor. The group is notable for emphasizing massive exfiltration, with reported healthcare incidents involving hundreds of gigabytes of stolen patient data per breach, and it has been associated with extortion-focused operations in which data theft itself is used as primary leverage. DevMan2 has been linked to attacks on healthcare entities and healthcare-adjacent organizations, including specialized health-care companies and biotechnology firms. It has also been associated with activity affecting software suppliers serving national healthcare infrastructure. Reporting further ties the group to a sharp rise in data-leak-site activity in Thailand during 2025, where it emerged as a significant driver of victim listings. This indicates a strong operational focus on public shaming and leak-site-based coercion. Observed tradecraft attributed to DevMan2 centers on exfiltration and post-compromise extortion rather than confirmed encryption-first operations. In the healthcare intrusion set discussed alongside the group, phishing was a dominant initial access vector across the sector, and defenders highlighted the need for improved detection of persistence and exfiltration, but DevMan2-specific initial access and lateral movement techniques are not independently established at high confidence from the available facts. The strongest supported assessment is that DevMan2 conducts data theft at scale and uses stolen information for extortion, consistent with leak-site operations and the broader trend toward quieter, disruption-minimizing breaches. Aliases and naming variants include Devman2 and DevMan2. The group is also described as a successor to Devman.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat group known for massive data exfiltration affecting the healthcare sector.
Devman2 claimed responsibility for a cyber attack on DXS, a UK-based NHS software supplier, alleging the theft of 300 GB of data. The company reported minimal impact and no disruption to clinical services.
Devman2 is an emerging ransomware group that has rapidly targeted organizations in Thailand, causing a 69% spike in attacks in Q3 2025. It is the successor to the original Devman group.
Relative newcomer described as a former affiliate of IncRansom and RansomHub; noted for large-scale patient data exfiltration and extortion against healthcare victims.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.