Key points
- Initial Access via Vulnerable Perimeter: The intrusion began with a compromised VPN appliance. While logging deficiencies obscured the exact entry mechanism, strong evidence suggests the Devman 2.0 operators leveraged a Remote Code Execution (RCE) exploit to hijack a valid account.
- Living Off the Land & Open-Source Tooling: The attackers maintained a low profile by abusing a pre-existing RMM tool (AnyDesk) to stage their payloads. They heavily relied on a suite of open-source tools for network discovery, credential access, and exfiltration.
- Aggressive Credential Scavenging: The threat actors didn’t stop at dumping LSASS memory with Mimikatz. They actively hunted for plaintext credentials by manually looting browser histories, accessing Google Password Manager pages, searches in mailbox, and scouring local files and intranet sites.
- Clever Masquerading for Persistence: Lateral movement was conducted primarily via RDP. To maintain access, the attackers created a new highly privileged domain account deceptively named fortibackup to blend in with normal administrative activity.
- Significant OpSec Failures: The attackers’ impatience led to critical operational security mistakes. They left behind an rclone configuration file containing the plaintext credentials to their Mega drop-zone, and deployed C2 implants (Sliver and Meterpreter) that were either misconfigured or remained completely dormant;
- Impact & Swift Containment: While the group successfully exfiltrated a large amount of sensitive data to the Mega cloud platform, their ultimate goal of deploying ransomware was thwarted. Swift isolation triggered by the EDR solution successfully neutralized the threat before the encryption phase could begin.
Introduction and Threat Landscape
During July 2025 the Airbus Protect Incident Response team responded to a significant data breach, which we attributed with a high level of confidence to ransomware group Devman 2.0. This incident occurred within legacy IT systems where EDR coverage was only partially deployed.
Even if the scenario is a classical ransomware attack, the threat actor showed interesting behavior, and some tricks or mistakes that are less common.










