01
Apos is tracked as an affiliate-enabled ransomware service.1
The brand supplies shared capabilities, but affiliates can change access methods and tooling; incident scoping should follow observed behavior rather than assume one fixed playbook.
CARDS
Apos emerged in April 2024 as a financially motivated threat group distinguished by its operation as a data-broker or leak-only entity, foregoing traditional file encryption in favor of data exfiltration and threatening to publicize or sell stolen information. While initial activity was noted to taper off, the group has been observed seeking penetration testers for its affiliate programs, suggesting a potential professionalization or expansion of its operations. Some reporting suggests the group consists of Russian-speaking members, though their geographical base remains unconfirmed.
Directory Briefing
01
The brand supplies shared capabilities, but affiliates can change access methods and tooling; incident scoping should follow observed behavior rather than assume one fixed playbook.
02
The retained behavior points to credentials, remote access, phishing, or exposed services; preserve authentication, VPN, edge-device, email, and remote-administration evidence together.
03
Check for earlier credential use, remote sessions, administrative changes, and data access because public actor records often understate the full pre-impact timeline.
04
Evidence includes credential or account abuse; response should cover privileged, service, remote-access, SaaS, and recovery identities—not just interactive user passwords.
05
Lateral movement, administrative access, and shared server infrastructure can turn a limited foothold into broad business interruption.
06
Prioritize unusual process ancestry, remote execution, account use, network paths, and administrative changes because tooling can change faster than the actor's operational requirements.
07
Endpoint, identity, network, cloud, email, and backup logs provide the cross-check needed when the actor's public record does not clearly describe defense evasion.
08
Collection or exfiltration behavior includes data staging and exfiltration; counsel and forensics need a shared record of what was accessed, staged, and transferred.
09
Retained targeting includes Construction of Buildings, Other Information Services, Software Publishers, Air Transportation, and Manufacturing across Argentina, Australia, Brazil, and Canada; translate those sectors into the organization's exposed systems and high-value data.
10
Align counsel, forensics, identity, recovery, insurance, communications, and regulatory analysis around one compromise timeline and one evidence-preservation plan.
Bottom Line Up Front
The brand supplies shared capabilities, but affiliates can change access methods and tooling; incident scoping should follow observed behavior rather than assume one fixed playbook.
The retained behavior points to credentials, remote access, phishing, or exposed services; preserve authentication, VPN, edge-device, email, and remote-administration evidence together.
Check for earlier credential use, remote sessions, administrative changes, and data access because public actor records often understate the full pre-impact timeline.
Evidence includes credential or account abuse; response should cover privileged, service, remote-access, SaaS, and recovery identities—not just interactive user passwords.
Lateral movement, administrative access, and shared server infrastructure can turn a limited foothold into broad business interruption.
Prioritize unusual process ancestry, remote execution, account use, network paths, and administrative changes because tooling can change faster than the actor's operational requirements.
Endpoint, identity, network, cloud, email, and backup logs provide the cross-check needed when the actor's public record does not clearly describe defense evasion.
Collection or exfiltration behavior includes data staging and exfiltration; counsel and forensics need a shared record of what was accessed, staged, and transferred.
Retained targeting includes Construction of Buildings, Other Information Services, Software Publishers, Air Transportation, and Manufacturing across Argentina, Australia, Brazil, and Canada; translate those sectors into the organization's exposed systems and high-value data.
Align counsel, forensics, identity, recovery, insurance, communications, and regulatory analysis around one compromise timeline and one evidence-preservation plan.
Decision Context
Apos emerged in April 2024 as a financially motivated threat group distinguished by its operation as a data-broker or leak-only entity, foregoing traditional file encryption in favor of data exfiltration and threatening to publicize or sell stolen information. While initial activity was noted to taper off, the group has been observed seeking penetration testers for its affiliate programs, suggesting a potential professionalization or expansion of its operations. Some reporting suggests the group consists of Russian-speaking members, though their geographical base remains unconfirmed.1,2
Actor Card Detail
Victimology
No named victim organizations are retained in the cited source artifacts for this profile. Countries and sectors are targeting context, not victim identities.
Identity
Aliases1
Source Boundary
SOCRadar is the retained baseline for this profile. IntelliOS preserves source labels as discovery and comparison signals until a cited source explicitly supports a merge, split, or actor-boundary change.
Targeting
Target Countries / Exposure1,2
Associated Activity1
ATT&CK IDs1
Campaign Context
No source-backed campaign or named operation association is currently retained for this actor card. Related campaign rows will appear here when SOCRadar, MITRE ATT&CK Campaigns, Microsoft, Google/Mandiant, CrowdStrike, CISA, or another retained public source ties the actor to a named campaign or operation.
Indicators
SOCRadar reports 976 IOCs for this profile. IntelliOS currently retains 59 cited public observable/context rows; this is not the full possible public-source IOC corpus.
Source coverage: 11 source groups tracked; 11 currently contribute retained observable or context rows.
Retained Observables
Showing 59 of 59
| Type | Value | Source |
|---|---|---|
| File Extension | .DEVMAN extension6 | DEVMAN |
| Tool / Process | Asia-Pacific market emphasis3 | WatchGuard ransomware tracker |
| Tool / Process | Data theft and encryption pressure via affiliate operations5 | Threat group profile |
| Tool / Process | Data-broker style extortion3 | WatchGuard ransomware tracker |
| Tool / Process | DevMan multi-platform affiliate behavior5 | Threat group profile |
| Tool / Process | Direct extortion3 | WatchGuard ransomware tracker |
| Tool / Process | Do not merge APOS platform row into DevMan operator row automatically2 | SOCRadar |
| Tool / Process | Double-extortion pressure3 | WatchGuard ransomware tracker |
| Tool / Process | DragonForce code lineage context5 | Threat group profile |
| Tool / Process | Initial access through phishing/social engineering10 | Ransomware trends and initial access patterns |
| Tool / Process | Initial access through public-facing application exposure10 | Ransomware trends and initial access patterns |
| Tool / Process | Initial access through valid credentials10 | Ransomware trends and initial access patterns |
| Tool / Process | Leak-only operation context4 | Apos ransomware group profile |
| Tool / Process | RaaS affiliate platform context5 | Threat group profile |
| Tool / Process | Small-to-mid-sized enterprise targeting3 | WatchGuard ransomware tracker |
| Tool / Process | Tracker-only confidence boundary for APOS-specific raw IOC counts2 | SOCRadar |
| ATT&CK ID | T1005 - Data from Local System10 | Ransomware trends and initial access patterns |
| ATT&CK ID | T1039 - Data from Network Shared Drive10 | Ransomware trends and initial access patterns |
| ATT&CK ID | T1041 - Exfiltration Over C2 Channel10 | Ransomware trends and initial access patterns |
| ATT&CK ID | T1059 - Command and Scripting Interpreter10 | Ransomware trends and initial access patterns |
| ATT&CK ID | T1078 - Valid Accounts10 | Ransomware trends and initial access patterns |
| ATT&CK ID | T1083 - File and Directory Discovery10 | Ransomware trends and initial access patterns |
| ATT&CK ID | T1190 - Exploit Public-Facing Application10 | Ransomware trends and initial access patterns |
| ATT&CK ID | T1486 - Data Encrypted for Impact / affiliate context6 | DEVMAN |
| ATT&CK ID | T1566 - Phishing10 | Ransomware trends and initial access patterns |
| ATT&CK ID | T1567 - Exfiltration Over Web Service10 | Ransomware trends and initial access patterns |
| ATT&CK ID | T1657 - Financial Theft / extortion-pressure context10 | Ransomware trends and initial access patterns |
| Alias / Related Name | Apos2 | SOCRadar |
| Alias / Related Name | Apos data-broker operation2 | SOCRadar |
| Alias / Related Name | APOS ransomware2 | SOCRadar |
| Alias / Related Name | Apos Security2 | SOCRadar |
| Alias / Related Name | DevMan affiliate context5 | Threat group profile |
| Malware Family | DevMan ransomware6 | DEVMAN |
| Malware Family | DragonForce-derived ransomware context6 | DEVMAN |
| Malware Family | Qilin affiliate/platform context5 | Threat group profile |
| Malware Family | RansomHub affiliate/platform context5 | Threat group profile |
| Campaign Context | April-July 2025: DevMan affiliate/operator reporting linked activity across Qilin, APOS, DragonForce, and RansomHub platforms.7 | DevMan ransomware threat actor report |
| Campaign Context | IntelliOS excludes raw victim lists, leaked files, leak-site URLs, contact IDs, Tox IDs, ransom notes, negotiation material, payment information, raw credentials/access data, and unsupported claims from the APOS card. | Retained source |
| Campaign Context | November 2024: WatchGuard first-seen date for Apos Security as a data-broker extortion entry.3 | WatchGuard ransomware tracker |
| CLASSIFICATION | RansomLook describes Apos as a data-broker or leak-only operation rather than a traditional file-encryption ransomware family.4 | Apos ransomware group profile |
| CLASSIFICATION | SOCRadar retains Apos as a ransomware actor row; WatchGuard tracks Apos Security as a data-broker direct/double-extortion entry first seen in November 2024.3 | WatchGuard ransomware tracker |
| OBSERVABLE | Analyst1 describes DevMan formalizing a RaaS platform after operating on modified DragonForce code; IntelliOS records this as operator/platform context, not APOS sample proof.8 | Devman's RaaS launch |
| OBSERVABLE | CERT-IL reports DevMan as an affiliate of several RaaS programs, mainly Qilin, APOS, and DragonForce, while tracking at least 54 DevMan claims as of July 2025.7 | DevMan ransomware threat actor report |
| OBSERVABLE | Vectra frames DevMan as part of recurring ransomware rebrand/lineage behavior from Conti to Black Basta to DevMan; IntelliOS uses that as lineage context only.9 | From Conti to Black Basta to DevMan |
| OBSERVABLE | WatchGuard's Apos Security tracker row exposes raw TOR/Tox/contact material; IntelliOS intentionally excludes those raw channels.3 | WatchGuard ransomware tracker |
| REGION | Africa4 | Apos ransomware group profile |
| REGION | Asia4 | Apos ransomware group profile |
| REGION | Asia-Pacific5 | Threat group profile |
| REGION | Europe4 | Apos ransomware group profile |
| REGION | Global exposure4 | Apos ransomware group profile |
| SECTOR | Construction4 | Apos ransomware group profile |
| SECTOR | Consumer services4 | Apos ransomware group profile |
| SECTOR | Healthcare4 | Apos ransomware group profile |
| SECTOR | Organizations represented in leak-site claims4 | Apos ransomware group profile |
| SECTOR | Public services4 | Apos ransomware group profile |
| SECTOR | Small and midsize enterprises5 | Threat group profile |
| SECTOR | Technology4 | Apos ransomware group profile |
| SOURCE_BOUNDARY | APOS-specific public technical artifacts are thin; stronger malware-detail sources currently describe DevMan/DragonForce lineage rather than standalone APOS samples.6 | DEVMAN |
| SOURCE_BOUNDARY | Halcyon and CERT-IL place DevMan as an affiliate/operator context across Qilin, DragonForce, Apos, and RansomHub; IntelliOS does not merge the APOS platform row into the DevMan actor row automatically.5 | Threat group profile |
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar2 | 976 | 6 | Reported IOC count and SOCRadar-backed observable rows retained in IntelliOS. |
| SOCRadar1 | N/A | 1 | Public observables or source-context rows retained and displayed. |
| SOCRadar2 | N/A | 6 | Public observables or source-context rows retained and displayed. |
| WatchGuard3 | N/A | 8 | Public observables or source-context rows retained and displayed. |
| RansomLook4 | N/A | 12 | Public observables or source-context rows retained and displayed. |
| Halcyon5 | N/A | 10 | Public observables or source-context rows retained and displayed. |
| Broadcom6 | N/A | 5 | Public observables or source-context rows retained and displayed. |
| Israel National Cyber Directorate / CERT-IL7 | N/A | 2 | Public observables or source-context rows retained and displayed. |
| Analyst18 | N/A | 1 | Public observables or source-context rows retained and displayed. |
| Vectra AI9 | N/A | 1 | Public observables or source-context rows retained and displayed. |
| Red Canary10 | N/A | 13 | Public observables or source-context rows retained and displayed. |
Actor Chronology
No source-backed actor-activity dates are currently retained. Publication and record-maintenance dates are not promoted into activity dates.
IntelliOS Intel Products
None Found
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | Apos | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | Apos | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for Apos.
No possible same-actor, alias reuse, sub-cluster, duplicate-boundary, or external-source collision is currently retained for this actor.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| None retained | No candidate records | No shared evidence recorded | No collision action needed. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor/ransomware | Threat actor directory source for profile fields and reported activity. |
| 2 | SOCRadar Actor Profile https://socradar.io/free-tools/ransomware-intelligence/groups/apos | Actor-specific source for ransomware profile metadata and reported IOC counts when available. |
| 3 | WatchGuard ransomware tracker: Apos Security https://www.watchguard.com/wgrd-security-hub/ransomware-tracker/apos-security | Ransomware Tracker |
| 4 | Apos ransomware group profile https://www.ransomlook.io/group/apos | Ransomware Tracker |
| 5 | Threat group profile: DevMan https://www.halcyon.ai/threat-group/devman | Threat Actor Profile |
| 6 | DEVMAN: a new DragonForce ransomware variant https://www.broadcom.com/support/security-center/protection-bulletin/devman-a-new-dragonforce-ransomware-variant | Malware Analysis |
| 7 | DevMan ransomware threat actor report https://www.gov.il/BlobFolder/reports/alert_1907/he/ALERT-CERT-IL-W-1907.pdf | Government Threat Intelligence |
| 8 | Devman's RaaS launch https://analyst1.com/devmans-raas-launch-the-affiliate-who-aims-to-become-the-boss/ | Threat Actor Reporting |
| 9 | From Conti to Black Basta to DevMan https://www.vectra.ai/blog/from-conti-to-black-basta-to-devman-the-endless-ransomware-rebrand | Ransomware Lineage Analysis |
| 10 | Ransomware trends and initial access patterns https://redcanary.com/threat-detection-report/trends/ransomware/ | Ransomware Landscape Report |