DevMan RaaS Operation: Centralized Portal and Affiliate Management
DevMan is a ransomware-as-a-service (RaaS) operation that emerged in April 2025, initially as an affiliate for Qilin, DragonForce, Apos, and RansomHub before…
MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.
DevMan is a ransomware-as-a-service (RaaS) operation that emerged in April 2025, initially as an affiliate for Qilin, DragonForce, Apos, and RansomHub before…
Funky Mantis is the name assigned by Swiss cybersecurity company PRODAFT to track the DevMan ransomware-as-a-service operation. The group operates a centralized…
Threat actors linked to the Cl0p ransomware group are actively exploiting vulnerabilities in internet-exposed PTC Windchill and FlexPLM deployments as part of…
Chubby Scorpius was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs,…
FIN11 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Graceful Spider was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs,…
Lace Tempest was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs,…
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate…
ClickFake Interview is a threat cluster tracked by Sekoia, associated with North Korea-aligned actors. It uses ClickFix-like lures to deceive targets into…
Golden Chickens, also tracked as Venom Spider and TAG-195, is a financially motivated malware-as-a-service developer. It has resurfaced with four new malware…