Advertisement
Cyber CrimeDeveloping Story

DevMan RaaS Formalizes Affiliate Control

A centralized portal upgrade aims to standardize affiliate workflows and tighten operational management for the DevMan ransomware group.

··2 hours ago·2 min read
a close up of a server's nameplates on the side of a
Photo by Marc PEZIN on Unsplash
Advertisement

The operators behind the DevMan ransomware-as-a-service (RaaS) scheme have shifted to a highly structured, centralized management model. By deploying a dedicated web platform, the group has moved beyond informal chat-based coordination to a system that governs everything from payload generation to financial settlement and victim management.

Centralizing the Ransomware Workflow

Security researchers at PRODAFT are monitoring these operations under the designation Funky Mantis. The group’s evolution into a standalone RaaS entity followed its initial activity as an affiliate for other ransomware programs. The current version of their platform, v3, introduced in January 2026, integrates a suite of administrative tools designed to formalize the lifecycle of an intrusion.

The portal combined build generation, finance, victim chat, support, victim records, teams, and payout functions.

— PRODAFT, a Swiss cybersecurity company

This platform enforces a rigid governance model, requiring curator approval for team formation and limiting affiliate autonomy. Administrators actively monitor progress, maintaining the right to intervene in victim communications if an affiliate fails to meet expectations or violates established operational tempo.

Quantifiable Operational Metrics

  • 184 total victims claimed by the group to date.
  • 80-20% revenue split between affiliates and the core RaaS program.
  • 5 distinct operational roles identified within the group's hierarchy.
  • 3 MiB threshold for file encryption depth.
  • 2-3 day completion window for attack operations.

Specialized Targets and SCADA Capabilities

DevMan’s operational policy highlights a strategic focus on industrial environments. The threat actors have reportedly developed a SCADA locker capable of forcing industrial control systems to operate beyond their safety thresholds, aiming to induce physical hardware failure. While the group maintains a policy against targeting child-related healthcare entities, they explicitly encourage attacks against critical infrastructure.

The Insider Threat Allegations

Recent scrutiny has also extended to the research community, following accusations involving the security firm Huntress. Ben Folland, a former employee, alleged that a current Huntress researcher disclosed sensitive law enforcement communications to a DevMan actor in December 2025. Huntress CEO Kyle Hanslovan acknowledged the exchange, characterizing the researcher’s actions as "poor judgment" rather than illegal conduct, though the incident has ignited a broader debate regarding the boundaries of threat intelligence engagement.

Operational Consequences for Organizations

The formalization of the DevMan platform suggests that ransomware operators are increasingly adopting corporate-style management to improve their success rates and operational efficiency. For organizations, the primary risk remains the group's access to highly modular, environment-specific lockers. Defending against these structured operations requires a shift toward phishing-resistant multi-factor authentication (MFA) and the rigorous rotation of credentials for VPNs and backup tooling. As these groups refine their ability to coordinate multiple intrusions simultaneously, the capability to quickly identify and revoke compromised administrative access remains a critical defensive priority.

#ransomware#cybercrime#threat intelligence#insider threat#scada

Sources

Xploitwire Editorial Team

Xploitwire Newsroom

This article's narrative text was drafted by AI (Google Gemini) from the sources listed above, and passed through our automated fact-check gate before publication. It has not been individually reviewed by a human editor prior to going live. Our AI Policy →

← Back to all stories
Advertisement