DevMan RaaS Formalizes Affiliate Control
A centralized portal upgrade aims to standardize affiliate workflows and tighten operational management for the DevMan ransomware group.
The operators behind the DevMan ransomware-as-a-service (RaaS) scheme have shifted to a highly structured, centralized management model. By deploying a dedicated web platform, the group has moved beyond informal chat-based coordination to a system that governs everything from payload generation to financial settlement and victim management.
Centralizing the Ransomware Workflow
Security researchers at PRODAFT are monitoring these operations under the designation Funky Mantis. The group’s evolution into a standalone RaaS entity followed its initial activity as an affiliate for other ransomware programs. The current version of their platform, v3, introduced in January 2026, integrates a suite of administrative tools designed to formalize the lifecycle of an intrusion.
The portal combined build generation, finance, victim chat, support, victim records, teams, and payout functions.
— PRODAFT, a Swiss cybersecurity company
This platform enforces a rigid governance model, requiring curator approval for team formation and limiting affiliate autonomy. Administrators actively monitor progress, maintaining the right to intervene in victim communications if an affiliate fails to meet expectations or violates established operational tempo.
Quantifiable Operational Metrics
- 184 total victims claimed by the group to date.
- 80-20% revenue split between affiliates and the core RaaS program.
- 5 distinct operational roles identified within the group's hierarchy.
- 3 MiB threshold for file encryption depth.
- 2-3 day completion window for attack operations.
Specialized Targets and SCADA Capabilities
DevMan’s operational policy highlights a strategic focus on industrial environments. The threat actors have reportedly developed a SCADA locker capable of forcing industrial control systems to operate beyond their safety thresholds, aiming to induce physical hardware failure. While the group maintains a policy against targeting child-related healthcare entities, they explicitly encourage attacks against critical infrastructure.
The Insider Threat Allegations
Recent scrutiny has also extended to the research community, following accusations involving the security firm Huntress. Ben Folland, a former employee, alleged that a current Huntress researcher disclosed sensitive law enforcement communications to a DevMan actor in December 2025. Huntress CEO Kyle Hanslovan acknowledged the exchange, characterizing the researcher’s actions as "poor judgment" rather than illegal conduct, though the incident has ignited a broader debate regarding the boundaries of threat intelligence engagement.
Operational Consequences for Organizations
The formalization of the DevMan platform suggests that ransomware operators are increasingly adopting corporate-style management to improve their success rates and operational efficiency. For organizations, the primary risk remains the group's access to highly modular, environment-specific lockers. Defending against these structured operations requires a shift toward phishing-resistant multi-factor authentication (MFA) and the rigorous rotation of credentials for VPNs and backup tooling. As these groups refine their ability to coordinate multiple intrusions simultaneously, the capability to quickly identify and revoke compromised administrative access remains a critical defensive priority.
Sources
- The Hacker News Original source
Continue Reading
ShinyHunters Brand Used in $2K Scams
Threat actors are repurposing publicly leaked data to launch targeted sextortion campaigns demanding Bitcoin payments from breach victims.
Cyber CrimeNewOrigin Energy Investigates Data Breach
Australian energy provider Origin confirms unauthorized access to customer records amid claims of a multi-million user data ransom.
University Ransomware Risks Escalate
Higher education institutions face a shifting threat landscape as specialized ransomware operations increasingly prioritize university targets.