Skip to content

Mamona

Mamona is a ransomware family associated with the same criminal ecosystem behind BlackLock and later Global Group, and appears to have been used as an intermediate rebrand in that lineage during 2025.

Profile source: Mallory opens in a new tab

Mamona

Family profile

Mamona is a ransomware family associated with the same criminal ecosystem behind BlackLock and later Global Group, and appears to have been used as an intermediate rebrand in that lineage during 2025. Reporting links Mamona to the operator alias "$$$" and to ransomware-as-a-service activity advertised on Russian-language criminal forums. Operational overlaps with Global include shared infrastructure patterns and reuse of the same mutex value, indicating close code or operator continuity rather than a merely nominal relationship.

Mamona targets enterprise environments and is tied to extortion operations that combine data theft with file encryption. Its successor lineage demonstrates capabilities including deletion of shadow copies, anti-analysis measures, multithreaded encryption, custom ransom-note deployment, and pressure tactics centered on leaking stolen data. Campaigns associated with the Mamona-to-Global transition have used phishing-delivered malware chains in which deceptive Windows shortcut attachments and living-off-the-land execution led to ransomware deployment. Mamona has also been discussed in connection with BlackLock affiliates, Embargo-linked activity, and later intersections with DragonForce-related operations, reflecting the fluid affiliate and rebranding dynamics common in the contemporary ransomware ecosystem.

Mamona is best understood as a short-lived ransomware brand within a broader financially motivated RaaS cluster that evolved from BlackLock and was subsequently rebranded as Global Group. Victimology associated with that cluster includes healthcare and manufacturing organizations, though Mamona itself is primarily notable for its role in that lineage rather than for uniquely documented technical distinctions.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion

Operational record

1
YARA rules
2
Leak sites
0 available

Reported operators

Threat actors

1 named in public reporting
$$$

March 11, 2025 - the actor "$$$" behind BlackLock Ransomware announced the launch of a new project called Mamona Ransomware.

MITRE ATT&CK

Mamona in ATT&CK

2 distinct techniques

Reporting

Research mentioning Mamona

Jul 25
The Hacker News

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

Researchers say DevMan, also tracked as Funky Mantis, operated a centralized ransomware-as-a-service platform with a dedicated affiliate portal for payload generation, victim management, ransom negotiation, earnings tracking, and internal coordination. PRODAFT reported the group was active from late 2025 into early 2026, used an 80/20 affiliate revenue split, and claimed 184 victims, with the heaviest concentration in the United States across technology, healthcare, financial services, professional services, and government. The operation explicitly pursued hospitals, critical infrastructure, the public sector, and law enforcement, and advertised a separate encryptor for SCADA environments, underscoring its focus on high-impact targets. Technical reporting links DevMan’s malware to DragonForce/Conti lineage while showing the operation evolved beyond a simple variant. Earlier analysis described a DragonForce-based sample marked by the .DEVMAN extension, SMB share probing, rapid encryption, and a builder flaw that encrypted its own ransom notes; later reporting identified a Rust-based Devman Locker using ChaCha20-Poly1305, appending .devman21, dropping RESTORE_FILES.txt, mounting network shares, disabling defenses, deleting shadow copies and event logs, and inhibiting recovery. The latest portal version reportedly supports Windows, Linux, and ESXi lockers and includes features for privilege checks, lateral movement, and security-tool impairment, indicating a mature and centrally managed extortion operation.

Jul 23
Cyberveille

Funky Mantis (DevMan) : analyse complète d'un RaaS centralisé ciblant hôpitaux et infrastructures critiques | CyberVeille

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.