Ransomware Group intelligence
Devman
InactiveTrack Devman with 207 published victims and 3 known leak locations in a single intelligence view.
Overview
Devman is tracked by Breach House as a ransomware group with 207 published victims.
United States is currently the most targeted country in this dataset.
3 known leak locations are currently associated with this group.
Leak Status Distribution
No leak-status data available yet.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (3)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Onion service | Down checked 1h ago | wugurgyscp5rxpihef5vl6b6m5ont3b6sezhl7boboso2enib2k3q6qd.onion |
| Leak location 2 | Onion service | Down checked 1h ago | devmanblggk7ddrtqj3tsocnayow3bwnozab2s4yhv4shpv6ueitjzid.onion |
| Leak location 1 | Onion service | Down checked 1h ago | qljmlmp4psnn3wqskkf3alqquatymo6hntficb4rhq5n76kuogcv7zyd.onion |
Top Activity Sectors (16)
- Not identified 123
- Finance / Legal / Insurance 21
- Healthcare / Pharma 20
- Communication / Marketing 17
- Services 13
- Manufacturing / Engineering 7
- Transportation / Travel / Logistics 6
- IT 4
- Energy 3
- Telecommunications 3
- Construction / Real Estate 2
- Retail / E-commerce 1
- NGOs / Associations 1
- Agriculture / Food 1
- Hospitality / Food & Beverage / Tourism 1
- Education 1
Typical Attacks (9)
▼MITRE ATT&CK does not currently catalogue Devman, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: devman uses PowerShell scripts to execute malicious commands and stage ransomware payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: devman modifies registry run keys to maintain persistence by automatically launching ransomware after system reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: devman disables antivirus tools and security software to prevent detection and ensure ransomware execution proceeds undetected.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.016 Junk Code Insertion Stealth
What they do: devman inserts junk code into binaries to evade static analysis and pack malicious payloads for distribution.
What that means: Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
-
T1070.004 File Deletion Stealth
What they do: devman deletes Volume Shadow Copies and backup directories via command-line tools to eliminate recovery options.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: devman uses remote system discovery to map network endpoints and identify high-value targets for encryption.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: devman performs network share discovery to identify accessible remote directories for lateral movement and data targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1041 Exfiltration Over C2 Channel Exfiltration
What they do: devman exfiltrates stolen victim data through encrypted C2 channels before deploying ransomware for double extortion.
What that means: Adversaries may steal data by exfiltrating it over an existing command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: devman encrypts victim files using strong symmetric encryption, targeting critical data across local and network shares.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
!!!_READ_ME_!!!.txt
██████╗ ███████╗██╗ ██╗███╗ ███╗ █████╗ ███╗ ██╗ ██████╗ ██╗ ██╔══██╗██╔════╝██║ ██║████╗ ████║██╔══██╗████╗ ██║ ╚════██╗ ███║ ██║ ██║█████╗ ██║ ██║██╔████╔██║███████║██╔██╗ ██║ █████╔╝ ╚██║ ██║ ██║██╔══╝ ╚██╗ ██╔╝██║╚██╔╝██║██╔══██║██║╚██╗██║ ██╔═══╝ ██║ ██████╔╝███████╗ ╚████╔╝ ██║ ╚═╝ ██║██║ ██║██║ ╚████║ ███████╗██╗██║ ╚═════╝ ╚══════╝ ╚═══╝ ╚═╝ ╚═╝╚═╝ ╚═╝╚═╝ ╚═══╝ ╚══════╝╚═╝╚═╝ ////////////////////////////////////////////////////////////////////////////// ///ENGLISH VERSION/////////////////////////////////////////////////////////// //////////////////////////////////////////////////////////////////////////// Dear, management and employees. We are the devman collective, and we are here to deliver some bad news. All of your files have been encrypted with a unbreakable encryption algorithm. However, this is not the only bad news for you. Around 100gb of your sensitive data,have been exfiltrated to our secure servers. What does that mean for you? It means that if you do not cooperate with us, not only will you lose access to your files, All of that sensitive data will be published online, causing irreparable damage to your reputation and potentially leading to legal consequences. The only way to decrypt your files, and to prevent the data leak is to cooperate with us, and get the decryption tool and unique key. What will happen if you do not cooperate with us? 1. Your files will remain encrypted forever. 2. Your sensitive data will be published online, and sent to your clients. 3. There is a high chance that you will face legal consequences for failing to protect your clients data, and violating data protection laws. How to cooperate with us? To obtain the decryption tool, you need to: 1. Contact us at: tygjm32hxyqienrgwxveiaw3azbjmfaln2znn2hldz2oe6v453ngwlyd.onion 2. Send your unique ID: [snip] 3. Receive a sample decryption of up to 4 files, and the file listing of exfiltrated data 4. We will provide payment instructions 5. After payment, you will receive decryption tool and unique key WARNING: - Do not modify encrypted files - Do not use third party software to restore files - Do not reinstall system If you violate these rules, your files may be permanently damaged. Unique ID: [snip] Backup contact (Qtox) 9D97F166730F865F793E2EA07B173C742A6302879DE1B0BBB03817A5A04B572FBD82F984981D
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (207)
Search, filter and paginate the victim timeline for Devman. Showing 101–200 of 207.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | pharmaciedesalizes.fr id23173 View details | France | Healthcare / Pharma | — | ||
|
pharmaciedesalizes.fr appears to be a French pharmacy-related healthcare site in the healthcare/pharma sector, reflecting the role of pharmacies in France’s broader healthcare system. In France, pharmacies dispense prescription and over-the-counter medicines and provide health advice and other patient-facing services within the national health framework. The site is therefore best understood as part of France’s healthcare and pharmaceutical services environment, with a local presence in France. It was listed as a ransomware victim associated with devman. |
||||||
| Ransomware | pharmaciedesalize.com.fr id24579 View details | France | Healthcare / Pharma | — | ||
|
Ransom: 50k 80gb |
||||||
| Ransomware | www.o****m*nt.com id23161 View details | Other | — | |||
|
Ransom: 1400000 USD |
||||||
| Ransomware | EMBASY OF BOLIVIA DC id23127 View details | Bolivia, Plurinational State of | Other | — | ||
|
Ransom: 200k 400gb |
||||||
| Ransomware | regionalurology.com id23126 View details | United States | Other | — | ||
|
Ransom: 200k 300gb |
||||||
| Ransomware | ****** embassy D.C id23065 View details | Other | — | |||
|
Ransom: 200000 USD |
||||||
| Ransomware | r******urology.com id22964 View details | Other | — | |||
|
Ransom: 250k 300gb |
||||||
| Ransomware | forestry.gov.jm id22963 View details | Jamaica | Other | — | ||
|
Ransom: 200000 USD |
||||||
| Ransomware | naturmaelk.dk id22832 View details | Denmark | Other | — | ||
|
Naturmælk is a Danish dairy company based in Tinglev, South Denmark, that is owned by the farmers who supply its milk. It operates as an organic dairy and produces milk and dairy products with an emphasis on sustainability, transparency, climate, biodiversity, and animal welfare. Company information and contact details identify Naturmælk as a small, ambitious mejeri serving the Danish market. Naturmælk (naturmaelk.dk) was listed as a ransomware victim associated with devman. |
||||||
| Ransomware | naturmaelk id24578 View details | Denmark | Other | — | ||
|
Ransom: 550000 USD |
||||||
| Ransomware | teeuwissen.com id22790 View details | Netherlands | Other | — | ||
|
Ransom: 370k 80gb |
||||||
| Ransomware | www.hameshakem.co.il id22787 View details | Israel | Other | — | ||
|
Ransom: 6kk 400gb exfiltrated |
||||||
| Ransomware | www.profimetrics.com id22707 View details | Portugal | Communication / Marketing | — | ||
|
Ransom: 50000 USD |
||||||
| Ransomware | e***.o*g id22706 View details | Other | — | |||
|
Ransom: 50000 USD |
||||||
| Ransomware | t*t*a**o**.com id22704 View details | Other | — | |||
|
Ransom: 500000 USD |
||||||
| Ransomware | a**h*y*in*er**t**nal.c*m id22703 View details | Other | — | |||
|
Ransom: 150000 USD |
||||||
| Ransomware | www.wrapex.ca id22660 View details | Canada | Other | — | ||
|
Wrapex Industrial Services Incorporated is a Canadian industrial services company based in Alberta, with locations in Edmonton, Rocky Mountain House, and Lloydminster. It provides industrial insulation, glycol tracing, utilidor, scaffolding, shrink wrapping, and access solutions for construction, maintenance, and turnaround projects across western Canada. Public company descriptions also place it in the construction sector and identify it as a private firm serving energy, petrochemical, pulp, and paper clients. It was listed as a ransomware victim associated with devman. |
||||||
| Ransomware | wrapex id24577 View details | Canada | Other | — | ||
|
Ransom: 780000 USD |
||||||
| Ransomware | pestbusters.com.sg id22644 View details | Singapore | Other | — | ||
|
PestBusters Singapore is a Singapore-based pest control company that provides pest control services not in connection with agriculture. Company records also note secondary construction-installation activity, and its office is registered at 139 Cecil Street, #05-01 YSY Building, Singapore. Its website describes it as one of Singapore’s leading providers of pest control services, with NEA-compliant protocols and services for residential and commercial clients. In threat-intelligence indexing, pestbusters.com.sg was listed as a ransomware victim associated with devman. |
||||||
| Ransomware | www.braswellsvc.com id22643 View details | United States | Other | — | ||
|
Braswell Services LLC is a Texas-based U.S. company operating in support services and logistics, with business lines that include procurement, manufacturing, kitting, transportation, and storage-related services. Public company listings also describe it as serving vehicle and industrial needs, including components, accessories, and related repair or freight activities. The company is associated with New Boston and the Hooks, Texas area, reflecting a regional operational footprint in the United States. In the threat-intelligence index, Braswell Services was listed as a ransomware victim associated with devman. |
||||||
| Ransomware | braswellsvc id24576 View details | United States | Other | — | ||
|
Ransom: 120000 USD | Note: 300gb exfiltrated |
||||||
| Ransomware | busaba.com id22642 View details | United Kingdom | Other | — | ||
|
Busaba.com is the website of Busaba Eathai Limited, a London-based Thai restaurant group in the UK hospitality sector. The company presents itself as a modern Bangkok dining brand built around Thai cooking, with restaurant services and a customer-facing privacy policy that references bookings, enquiries, offers and events. Public company data places Busaba Eathai Limited in London, England, and classifies it as a licensed restaurant business. It was listed as a ransomware victim associated with devman. |
||||||
| Ransomware | busaba id24575 View details | United Kingdom | Other | — | ||
|
Ransom: 580000 USD |
||||||
| Ransomware | www.chicagobotanic.org id22641 View details | United States | Other | — | ||
|
Chicago Botanic Garden is a nonprofit public garden in Glencoe, Illinois, in the United States, centered on a 385-acre landscape with 27 to 28 themed gardens and related visitor areas. It offers seasonal walks, tram tours, a café, a garden shop, plant information resources, membership, and educational programs, classes, and workshops for visitors and members. The site supports garden visits, learning activities, and plant discovery through collections, plant profiles, and conservation-related content. It was listed as a ransomware victim associated with devman. |
||||||
| Ransomware | chicagobotanic id24574 View details | United States | Other | — | ||
|
Ransom: 590000 USD |
||||||
| Ransomware | r3consulting.com id22640 View details | United States | Services | — | ||
|
r3consulting.com is the website of R3 Government Solutions, a professional services company based in Arlington, Virginia, United States. The firm says it provides services and solutions that help agencies address difficult staffing and organizational challenges, with work in federal human capital, human resources, and training. Company listings also place it in the Services sector and describe it as a US-based business with offices in Arlington and Marco Island. It was listed as a ransomware victim associated with devman. |
||||||
| Ransomware | r3consulting id24573 View details | United States | Services | — | ||
|
Ransom: 350000 USD | Note: 400gb stollen |
||||||
| Ransomware | ncgllc.com id22639 View details | United States | Services | — | ||
|
Ransom: 100000 USD |
||||||
| Ransomware | n**u***e**.dk id22638 View details | Other | — | |||
|
Ransom: 590000 USD |
||||||
| Ransomware | sacada.org id22637 View details | United States | Other | — | ||
|
Ransom: 100000 USD |
||||||
| Ransomware | promisedland.com.tw/h21 million USD...Time Remaining:---BUY Files id22416 View details | Taiwan, Province of China | Communication / Marketing | — | ||
|
1000000 USD |
||||||
| Ransomware | www.shimaogroup.com id22415 View details | China | Services | — | ||
|
91000000 USD |
||||||
| Ransomware | www.p***e*u**h***.us id22414 View details | United States | Other | — | ||
|
1700000 USD |
||||||
| Ransomware | www.s*i***gr*u*.com id22156 View details | Other | — | |||
|
91000000 USD |
||||||
| Ransomware | promisedland.com.tw id22109 View details | Taiwan, Province of China | Communication / Marketing | — | ||
|
1000000 USD |
||||||
| Ransomware | www.pure-chemical.com id22108 View details | India | Manufacturing / Engineering | — | ||
|
5000000 USD |
||||||
| Ransomware | ruff.com.br id21529 View details | Brazil | Other | — | ||
|
1000000 USD |
||||||
| Ransomware | www.diethelmtravel.com id21528 View details | Thailand | Transportation / Travel / Logistics | — | ||
|
www.diethelmtravel.com is the website of DTH Travel, formerly Diethelm Travel, a Thailand-based destination management company in the transportation and travel sector. The company provides tailor-made holidays, inbound travel services, and destination management across Asia, serving leisure and business travelers from its Bangkok base. Public directory and company materials describe a long-standing regional travel operator with offices and local partnerships in multiple Asian markets. It was listed as a ransomware victim associated with devman. |
||||||
| Ransomware | diethelmtravel id24572 View details | Thailand | Transportation / Travel / Logistics | — | ||
|
1800000 USD |
||||||
| Ransomware | kw****.tw id21482 View details | Taiwan, Province of China | Other | — | ||
|
1000000 USD |
||||||
| Ransomware | pr*****.tw id21481 View details | Taiwan, Province of China | Communication / Marketing | — | ||
|
1050000 USD |
||||||
| Ransomware | b*u*l*****.tw id21480 View details | Taiwan, Province of China | Other | — | ||
|
1100000 USD |
||||||
| Ransomware | ***.c*m.tw id21479 View details | Taiwan, Province of China | Other | — | ||
|
6000000 USD |
||||||
| Ransomware | pt.elis.com id21252 View details | Portugal | Other | — | ||
|
4000000 USD |
||||||
| Ransomware | pt.e*i*.com id21228 View details | Other | — | |||
|
4000000 USD |
||||||
| Ransomware | mol.go.th id21207 View details | Thailand | Other | — | ||
|
15000000 USD |
||||||
| Ransomware | eehc.gov.eg id21156 View details | Egypt | Other | — | ||
|
2270000 USD |
||||||
| Ransomware | solidere.com id21129 View details | Lebanon | Other | — | ||
|
Solidere is a Lebanese real estate company based in Beirut, with its headquarters in the Beirut Central District. The company’s stated objective is to acquire real estate properties and to finance and execute infrastructure works in the Beirut Central area, supporting redevelopment and related urban projects. Its website, solidere.com, serves as the company’s corporate presence and information channel. In threat-intelligence listings, solidere.com was associated with a ransomware victim entry tied to devman. |
||||||
| Ransomware | www.e***.gov.eg id21128 View details | Other | — | |||
|
2270000 USD |
||||||
| Ransomware | sol*d*r*.com id21108 View details | Other | — | |||
|
7250000 USD |
||||||
| Ransomware | Hong Kong Victim id20983 View details | Hong Kong | Other | — | ||
|
(To be disclosed)... |
||||||
| Ransomware | China Harbour Engineering Company id20982 View details | China | Manufacturing / Engineering | — | ||
|
450000 USD |
||||||
| Ransomware | TBD HONG KONG id20981 View details | Hong Kong | Other | — | ||
|
TBD... |
||||||
| Ransomware | c****gl*b*.com id20980 View details | Other | — | |||
|
1000000 USD |
||||||
| Ransomware | takachiho.co.jp id20979 View details | Japan | Other | — | ||
|
1000000 USD |
||||||
| Ransomware | elematec.com id20978 View details | Japan | Other | — | ||
|
Elematec Corporation is a Japan-based integrated service company in the electronics industry, headquartered in Tokyo, Japan. It describes itself as providing electronics-related services supported by a long-established client base and on-site capabilities, with offices and group operations across Japan and overseas. The company’s corporate information and network pages show a global business footprint spanning Asia and the Americas. Elematec.com was listed as a ransomware victim associated with devman. |
||||||
| Ransomware | elematec id24571 View details | Japan | Other | — | ||
|
10000000 USD |
||||||
| Ransomware | gotec.com id20977 View details | Switzerland | Other | — | ||
|
GOTEC Group is a specialist in surface treatment and bonding-agent coating for rubber, metal, and plastic parts, with a global industrial footprint across Europe, the Americas, and Asia. Its headquarters are in Wülfrath, Germany, and the company operates production and sales locations in multiple countries, including Switzerland-related business activity. Public company profiles describe GOTEC as a supplier to automotive and industrial customers, focused on coating and adhesion solutions for technical components. The domain gotec.com was listed as a ransomware victim associated with devman. |
||||||
| Ransomware | gotec id24570 View details | Switzerland | Other | — | ||
|
6450000 USD |
||||||
| Ransomware | NSSF KENYA /nssf.zip - first samle /nssfwriteup.html - writeup id20517 View details | Kenya | Other | — | — | |
|
NSSF Kenya is Kenya’s National Social Security Fund, a public-sector social security institution based in Kenya that administers social protection services for workers and employers. In threat-intelligence catalogs, it is referenced with related sample or writeup labels such as nssf.zip and nssfwriteup.html, which are used to index the incident record rather than describe the organization’s operations. The listing places the entity in the “Other” sector and frames it as a ransomware-related target in Kenya. It was listed as a ransomware victim associated with devman. |
||||||
| Ransomware | DHL THAILAND id20391 View details | Thailand | Other | — | — | |
|
TBD |
||||||
| Ransomware | lantro.com id20373 View details | Japan | Other | — | — | |
|
1.1 million USD |
||||||
| Ransomware | dmbarone.com id20251 View details | United States | Hospitality / Food & Beverage / Tourism | — | — | |
|
130k USD |
||||||
| Ransomware | Gobierno del Estado de Colima id20238 View details | Mexico | Other | — | — | |
|
TBD |
||||||
| Ransomware | www.nijar.es id20217 View details | Spain | Other | — | — | |
|
TBD |
||||||
| Ransomware | www.paragonradiology.com id20200 View details | United States | Other | — | — | |
|
200k USD |
||||||
| Ransomware | netstar.co.za id20199 View details | South Africa | Other | — | — | |
|
Netstar is a South African company in the transport and security technology space, best known for vehicle tracking and stolen-vehicle-recovery services. It says it pioneered the industry in South Africa in 1994 and provides nationwide customer support from offices in Midrand and other locations across the country. The company also references business and personal contact services through its website and branded regional offices. In threat-intelligence records, netstar.co.za was listed as a ransomware victim associated with devman. |
||||||
| Ransomware | netstar id24569 View details | South Africa | Other | — | — | |
|
1.2 million USD |
||||||
| Ransomware | NSSF KENYA id20137 View details | Kenya | Other | — | — | |
|
4.5 million USD |
||||||
| Ransomware | TBD KOREA id20135 View details | Korea, Republic of | Other | — | — | |
|
TBD |
||||||
| Ransomware | TBD HONK KONG id20134 View details | Hong Kong | Other | — | — | |
|
TBD |
||||||
| Ransomware | TBD GREECE id20133 View details | Greece | Other | — | — | |
|
TBD |
||||||
| Ransomware | TOHO-CO id20132 View details | Japan | Other | — | — | |
|
120k |
||||||
| Ransomware | TBD KENYA id20131 View details | Kenya | Other | — | — | |
|
TBD |
||||||
| Ransomware | piriou.vn id20130 View details | Viet Nam | Other | — | — | |
|
Piriou Vietnam is a shipbuilding company based in Ho Chi Minh City, Vietnam, with operations also associated with Long An province. It builds medium-sized aluminum and steel vessels to European standards, emphasizing high added value and competitive pricing. Company materials describe it as PIRIOU VIETNAM, formerly SEAS South East Asia Shipyard, and place it in the ship and boat building sector. The entity was listed as a ransomware victim associated with devman. |
||||||
| Ransomware | piriou id24568 View details | Viet Nam | Other | — | — | |
|
383K USD |
||||||
| Ransomware | tvgoiania.com.br id19966 View details | Brazil | Other | — | — | |
|
80K USD |
||||||
| Ransomware | Pienaar Brothers id19959 View details | South Africa | Other | — | — | |
|
590K USD |
||||||
| Ransomware | Victim from Japan id19958 View details | Japan | Other | — | — | |
|
TBD |
||||||
| Ransomware | dailynews.co.th id19944 View details | Thailand | Other | — | — | |
|
dailynews.co.th is the online edition of Daily News, a Thai-language daily newspaper based in Bangkok and distributed nationwide. Its website publishes general news coverage for Thailand, including latest news, breaking stories, sports, entertainment, health, and current affairs. The publication describes itself as an internet daily newspaper offering broad news analysis and up-to-date reporting for readers in Thailand. In threat-intelligence listings, dailynews.co.th appears as a ransomware victim associated with devman, with Thailand recorded as the country and Other as the sector. |
||||||
| Ransomware | DAILY NEWS THAILAND id24567 View details | Thailand | Other | — | — | |
|
375K USD |
||||||
| Ransomware | gmanetwork.com id19934 View details | Philippines | Telecommunications | — | — | |
|
gmanetwork.com is the official website of GMA Network, Inc., a Philippine media and broadcasting company based in Quezon City, Metro Manila. GMA Network operates television and radio services and presents news, entertainment, and corporate information through its public web presence. The company describes itself as the Philippines' leading broadcast network, with a broad portfolio of programs and media-related businesses. In threat-intelligence catalogs, gmanetwork.com was listed as a ransomware victim associated with devman. |
||||||
| Ransomware | GMA NETWORK id24566 View details | Philippines | Telecommunications | — | — | |
|
2.5 million USD |
||||||
| Ransomware | https://www.gmanetwork.com/news/ id19933 View details | Philippines | Other | — | — | |
|
https://www.gmanetwork.com/news/ is the official news portal of GMA Network, one of the largest television and media networks in the Philippines, delivering latest Philippine and international news coverage. The site offers real-time updates on politics, business, science, technology, and entertainment, serving audiences across the Philippines and globally. It operates from Quezon City and is recognized as a leading and trusted source for broadcast and digital news in the country. The portal was listed as a ransomware victim associated with the threat actor devman. |
||||||
| Ransomware | https://pestbusters.com.sg/ id19740 View details | Singapore | Other | — | — | |
|
PestBusters is one of Singapore's leading providers of pest control services, combining expertise with rigorous, NEA-compliant protocols for residential and commercial clients. For over 30 years, the company pioneered high-quality pest control in Singapore, delivering excellent service with compliance to environmental health and safety standards. As Asia's leading pest management experts, PestBusters offers innovative and comprehensive pest management services across the region. The company was listed as a ransomware victim associated with the threat actor devman. |
||||||
| Ransomware | pestbusters id24564 View details | Singapore | Other | — | — | |
|
100K USD |
||||||
| Ransomware | smvthailand.com id19685 View details | Thailand | Other | — | — | |
|
375K USD |
||||||
| Ransomware | Chinese Healthcare Organisation id19680 View details | China | Healthcare / Pharma | — | — | |
|
TBD |
||||||
| Ransomware | Singapour Factory id19679 View details | Singapore | Manufacturing / Engineering | — | — | |
|
TBD |
||||||
| Ransomware | South African IT firm id19652 View details | South Africa | Other | — | — | |
|
TBD |
||||||
| Ransomware | South African Hr company id19651 View details | South Africa | Services | — | — | |
|
TBD |
||||||
| Ransomware | dovesit.co.za id19650 View details | South Africa | Other | — | — | |
|
550k USD |
||||||
| Ransomware | EU victim id19342 View details | Other | — | — | ||
|
(To be discoled) |
||||||
| Ransomware | China Harbour Engeneiring Company FILE SAMPLE 1 avaliable /CHEC/CHECsample.zip id19326 View details | China | Services | — | — | |
|
China Harbour Engineering Company Ltd. (CHEC) is a Beijing-based Chinese services and infrastructure contractor founded in 1980 and part of China Communications Construction Company Ltd. It provides EPC, BOT, and PPP services across marine engineering, dredging and reclamation, roads and bridges, railways, airports, and related civil works. The company also supports public and private sector infrastructure projects with equipment supply and installation and broader engineering services. China Harbour Engeneiring Company FILE SAMPLE 1 avaliable /CHEC/CHECsample.zip was listed as a ransomware victim associated with devman. |
||||||
| Ransomware | Premier Meats South Africa id19268 View details | South Africa | Communication / Marketing | — | — | |
|
(90k USD) |
||||||
| Ransomware | Feel Four id19267 View details | Singapore | Other | — | — | |
|
60k USD |
||||||
| Ransomware | Singapour Victim id19266 View details | Singapore | Other | — | — | |
|
(To be discoled) |
||||||
| Ransomware | Honk Kong Victim id19265 View details | Hong Kong | Other | — | — | |
|
(To be discoled) |
||||||
| Ransomware | China Harbour Engeneiring Company id19264 View details | China | Services | — | — | |
|
450k USD |
||||||
| Ransomware | FEELFOUR id19143 View details | Singapore | Other | — | — | |
|
70k USD |
||||||