CARDS
CARDS
Apos emerged in April 2024 as a financially motivated threat group distinguished by its operation as a data-broker or leak-only entity, foregoing traditional file encryption in favor of data exfiltration and threatening to publicize or sell stolen information. While initial activity was noted to taper off, the group has been observed seeking penetration testers for its affiliate programs, suggesting a potential professionalization or expansion of its operations. Some reporting suggests the group consists of Russian-speaking members, though their geographical base remains unconfirmed.
This profile is generated from the same canonical actor-card record used by the Threat Actor Cards directory, so aliases, targeting fields, activity notes, and source links stay aligned as the database is enriched.
Actor Card Detail
Identity
Aliases1
Source Boundary
SOCRadar is the retained baseline for this profile. IntelliOS preserves source labels as discovery and comparison signals until a cited source explicitly supports a merge, split, or actor-boundary change.
Targeting
Associated Activity1
ATT&CK IDs1
Campaign Context
No source-backed campaign or named operation association is currently retained for this actor card. Related campaign rows will appear here when SOCRadar, MITRE ATT&CK Campaigns, Microsoft, Google/Mandiant, CrowdStrike, CISA, or another retained public source ties the actor to a named campaign or operation.
Indicators
SOCRadar reports 976 IOCs for this profile. IntelliOS currently retains 59 cited public observable/context rows; this is not the full possible public-source IOC corpus.
Source coverage: 11 source groups tracked; 11 currently contribute retained observable or context rows.
Retained Observables
Showing 59 of 59
| Type | Value | Source |
|---|---|---|
| File Extension | .DEVMAN extension6 | DEVMAN |
| Tool / Process | Asia-Pacific market emphasis3 | WatchGuard ransomware tracker |
| Tool / Process | Data theft and encryption pressure via affiliate operations5 | Threat group profile |
| Tool / Process | Data-broker style extortion3 | WatchGuard ransomware tracker |
| Tool / Process | DevMan multi-platform affiliate behavior5 | Threat group profile |
| Tool / Process | Direct extortion3 | WatchGuard ransomware tracker |
| Tool / Process | Do not merge APOS platform row into DevMan operator row automatically2 | SOCRadar |
| Tool / Process | Double-extortion pressure3 | WatchGuard ransomware tracker |
| Tool / Process | DragonForce code lineage context5 | Threat group profile |
| Tool / Process | Initial access through phishing/social engineering10 | Ransomware trends and initial access patterns |
| Tool / Process | Initial access through public-facing application exposure10 | Ransomware trends and initial access patterns |
| Tool / Process | Initial access through valid credentials10 | Ransomware trends and initial access patterns |
| Tool / Process | Leak-only operation context4 | Apos ransomware group profile |
| Tool / Process | RaaS affiliate platform context5 | Threat group profile |
| Tool / Process | Small-to-mid-sized enterprise targeting3 | WatchGuard ransomware tracker |
| Tool / Process | Tracker-only confidence boundary for APOS-specific raw IOC counts2 | SOCRadar |
| ATT&CK ID | T1005 - Data from Local System10 | Ransomware trends and initial access patterns |
| ATT&CK ID | T1039 - Data from Network Shared Drive10 | Ransomware trends and initial access patterns |
| ATT&CK ID | T1041 - Exfiltration Over C2 Channel10 | Ransomware trends and initial access patterns |
| ATT&CK ID | T1059 - Command and Scripting Interpreter10 | Ransomware trends and initial access patterns |
| ATT&CK ID | T1078 - Valid Accounts10 | Ransomware trends and initial access patterns |
| ATT&CK ID | T1083 - File and Directory Discovery10 | Ransomware trends and initial access patterns |
| ATT&CK ID | T1190 - Exploit Public-Facing Application10 | Ransomware trends and initial access patterns |
| ATT&CK ID | T1486 - Data Encrypted for Impact / affiliate context6 | DEVMAN |
| ATT&CK ID | T1566 - Phishing10 | Ransomware trends and initial access patterns |
| ATT&CK ID | T1567 - Exfiltration Over Web Service10 | Ransomware trends and initial access patterns |
| ATT&CK ID | T1657 - Financial Theft / extortion-pressure context10 | Ransomware trends and initial access patterns |
| Alias / Related Name | Apos2 | SOCRadar |
| Alias / Related Name | Apos data-broker operation2 | SOCRadar |
| Alias / Related Name | APOS ransomware2 | SOCRadar |
| Alias / Related Name | Apos Security2 | SOCRadar |
| Alias / Related Name | DevMan affiliate context5 | Threat group profile |
| Malware Family | DevMan ransomware6 | DEVMAN |
| Malware Family | DragonForce-derived ransomware context6 | DEVMAN |
| Malware Family | Qilin affiliate/platform context5 | Threat group profile |
| Malware Family | RansomHub affiliate/platform context5 | Threat group profile |
| Campaign Context | April-July 2025: DevMan affiliate/operator reporting linked activity across Qilin, APOS, DragonForce, and RansomHub platforms.7 | DevMan ransomware threat actor report |
| Campaign Context | IntelliOS excludes raw victim lists, leaked files, leak-site URLs, contact IDs, Tox IDs, ransom notes, negotiation material, payment information, raw credentials/access data, and unsupported claims from the APOS card. | Retained source |
| Campaign Context | November 2024: WatchGuard first-seen date for Apos Security as a data-broker extortion entry.3 | WatchGuard ransomware tracker |
| CLASSIFICATION | RansomLook describes Apos as a data-broker or leak-only operation rather than a traditional file-encryption ransomware family.4 | Apos ransomware group profile |
| CLASSIFICATION | SOCRadar retains Apos as a ransomware actor row; WatchGuard tracks Apos Security as a data-broker direct/double-extortion entry first seen in November 2024.3 | WatchGuard ransomware tracker |
| OBSERVABLE | Analyst1 describes DevMan formalizing a RaaS platform after operating on modified DragonForce code; IntelliOS records this as operator/platform context, not APOS sample proof.8 | Devman's RaaS launch |
| OBSERVABLE | CERT-IL reports DevMan as an affiliate of several RaaS programs, mainly Qilin, APOS, and DragonForce, while tracking at least 54 DevMan claims as of July 2025.7 | DevMan ransomware threat actor report |
| OBSERVABLE | Vectra frames DevMan as part of recurring ransomware rebrand/lineage behavior from Conti to Black Basta to DevMan; IntelliOS uses that as lineage context only.9 | From Conti to Black Basta to DevMan |
| OBSERVABLE | WatchGuard's Apos Security tracker row exposes raw TOR/Tox/contact material; IntelliOS intentionally excludes those raw channels.3 | WatchGuard ransomware tracker |
| REGION | Africa4 | Apos ransomware group profile |
| REGION | Asia4 | Apos ransomware group profile |
| REGION | Asia-Pacific5 | Threat group profile |
| REGION | Europe4 | Apos ransomware group profile |
| REGION | Global exposure4 | Apos ransomware group profile |
| SECTOR | Construction4 | Apos ransomware group profile |
| SECTOR | Consumer services4 | Apos ransomware group profile |
| SECTOR | Healthcare4 | Apos ransomware group profile |
| SECTOR | Organizations represented in leak-site claims4 | Apos ransomware group profile |
| SECTOR | Public services4 | Apos ransomware group profile |
| SECTOR | Small and midsize enterprises5 | Threat group profile |
| SECTOR | Technology4 | Apos ransomware group profile |
| SOURCE_BOUNDARY | APOS-specific public technical artifacts are thin; stronger malware-detail sources currently describe DevMan/DragonForce lineage rather than standalone APOS samples.6 | DEVMAN |
| SOURCE_BOUNDARY | Halcyon and CERT-IL place DevMan as an affiliate/operator context across Qilin, DragonForce, Apos, and RansomHub; IntelliOS does not merge the APOS platform row into the DevMan actor row automatically.5 | Threat group profile |
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar2 | 976 | 6 | Reported IOC count and SOCRadar-backed observable rows retained in IntelliOS. |
| SOCRadar1 | N/A | 1 | Public observables or source-context rows retained and displayed. |
| SOCRadar2 | N/A | 6 | Public observables or source-context rows retained and displayed. |
| WatchGuard3 | N/A | 8 | Public observables or source-context rows retained and displayed. |
| RansomLook4 | N/A | 12 | Public observables or source-context rows retained and displayed. |
| Halcyon5 | N/A | 10 | Public observables or source-context rows retained and displayed. |
| Broadcom6 | N/A | 5 | Public observables or source-context rows retained and displayed. |
| Israel National Cyber Directorate / CERT-IL7 | N/A | 2 | Public observables or source-context rows retained and displayed. |
| Analyst18 | N/A | 1 | Public observables or source-context rows retained and displayed. |
| Vectra AI9 | N/A | 1 | Public observables or source-context rows retained and displayed. |
| Red Canary10 | N/A | 13 | Public observables or source-context rows retained and displayed. |
IntelliOS Intel Products
None Found
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | Apos | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | Apos | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor/ransomware | Baseline actor-card corpus source for retained profile fields. |
| 2 | SOCRadar Actor Profile https://socradar.io/free-tools/ransomware-intelligence/groups/apos | Per-actor SOCRadar profile source for ransomware profile metadata and IOC count when available. |
| 3 | WatchGuard ransomware tracker: Apos Security https://www.watchguard.com/wgrd-security-hub/ransomware-tracker/apos-security | Ransomware Tracker |
| 4 | Apos ransomware group profile https://www.ransomlook.io/group/apos | Ransomware Tracker |
| 5 | Threat group profile: DevMan https://www.halcyon.ai/threat-group/devman | Threat Actor Profile |
| 6 | DEVMAN: a new DragonForce ransomware variant https://www.broadcom.com/support/security-center/protection-bulletin/devman-a-new-dragonforce-ransomware-variant | Malware Analysis |
| 7 | DevMan ransomware threat actor report https://www.gov.il/BlobFolder/reports/alert_1907/he/ALERT-CERT-IL-W-1907.pdf | Government Threat Intelligence |
| 8 | Devman's RaaS launch https://analyst1.com/devmans-raas-launch-the-affiliate-who-aims-to-become-the-boss/ | Threat Actor Reporting |
| 9 | From Conti to Black Basta to DevMan https://www.vectra.ai/blog/from-conti-to-black-basta-to-devman-the-endless-ransomware-rebrand | Ransomware Lineage Analysis |
| 10 | Ransomware trends and initial access patterns https://redcanary.com/threat-detection-report/trends/ransomware/ | Ransomware Landscape Report |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for Apos.
No possible same-actor, alias reuse, sub-cluster, duplicate-boundary, or external-source collision is currently retained for this actor.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| None retained | No candidate records | No shared evidence recorded | No collision action needed. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |