Skip to content

Mamona

Mamona is a ransomware family linked to the operator behind BlackLock and Eldorado and later superseded by Global Group ransomware.

Profile source: Mallory opens in a new tab

Mamona

Family profile

Mamona is a ransomware family linked to the operator behind BlackLock and Eldorado and later superseded by Global Group ransomware. It emerged in 2025 as part of a rapid rebranding pattern within the ransomware-as-a-service ecosystem, where operators rotate brands, infrastructure, and affiliate programs to evade disruption and preserve access to partners. Mamona has been associated with leak-site activity and with broader overlap among BlackLock affiliates, DragonForce-related activity, and other ransomware actors operating in the same criminal marketplace.

Mamona is best understood as a ransomware strain rather than a long-lived standalone operation. Reporting ties it to the same actor alias associated with BlackLock and Eldorado, and later reporting identifies Global Group as its successor. This lineage indicates continuity in operator tradecraft and business model rather than an isolated malware family. Mamona was also referenced in the context of ransomware leak-site defacements during apparent inter-group conflict involving DragonForce, underscoring its place in a fragmented and competitive affiliate-driven ecosystem.

High-confidence reporting does not provide a full technical profile for Mamona itself comparable to its successor, but the family is directly associated with extortion-oriented ransomware operations. It targeted enterprise environments through an affiliate model and was part of a cluster of brands active across multiple sectors. Mamona has been discussed alongside campaigns intersecting with BlackLock affiliates and the Embargo group, suggesting operational overlap within the broader ransomware underground. Later successor activity tied to Global Group shows phishing-based delivery using deceptive Windows shortcut files and offline-capable encryption, but those behaviors should be attributed to the successor family unless independently confirmed for Mamona.

Capabilities

  • Extortion

Operational record

1
YARA rules
2
Leak sites
0 available

Reported operators

Threat actors

1 named in public reporting
$$$

March 11, 2025 - the actor "$$$" behind BlackLock Ransomware announced the launch of a new project called Mamona Ransomware.

MITRE ATT&CK

Mamona in ATT&CK

2 distinct techniques

Reporting

Research mentioning Mamona

Jul 25
The Hacker News

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

Researchers say DevMan, also tracked as Funky Mantis, operated a centralized ransomware-as-a-service platform with a dedicated affiliate portal for payload generation, victim management, ransom negotiation, earnings tracking, and internal coordination. PRODAFT reported the group was active from late 2025 into early 2026, used an 80/20 affiliate revenue split, and claimed 184 victims, with the heaviest concentration in the United States across technology, healthcare, financial services, professional services, and government. The operation explicitly pursued hospitals, critical infrastructure, the public sector, and law enforcement, and advertised a separate encryptor for SCADA environments, underscoring its focus on high-impact targets. Technical reporting links DevMan’s malware to DragonForce/Conti lineage while showing the operation evolved beyond a simple variant. Earlier analysis described a DragonForce-based sample marked by the .DEVMAN extension, SMB share probing, rapid encryption, and a builder flaw that encrypted its own ransom notes; later reporting identified a Rust-based Devman Locker using ChaCha20-Poly1305, appending .devman21, dropping RESTORE_FILES.txt, mounting network shares, disabling defenses, deleting shadow copies and event logs, and inhibiting recovery. The latest portal version reportedly supports Windows, Linux, and ESXi lockers and includes features for privilege checks, lateral movement, and security-tool impairment, indicating a mature and centrally managed extortion operation.

Jul 23
Cyberveille

Funky Mantis (DevMan) : analyse complète d'un RaaS centralisé ciblant hôpitaux et infrastructures critiques | CyberVeille

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.