DevMan RaaS Portal v3 Centralizes Payload Builds and Affiliate Operations
The operators behind the DevMan ransomware-as-a-service (RaaS) scheme continue to run a dedicated web platform that lets affiliates generate payloads, track earnings, and coordinate victim negotiations from a single interface. Swiss cybersecurity firm PRODAFT tracks the centrally administered operation under the name "Funky Mantis," describing a portal that combines build generation, finance management, victim chat, support ticketing, victim records, team coordination, and payout processing. Administrators broker initial access alongside ransomware deployment, offering country-specific "networks" and enforcing two-to-three-day completion windows per engagement, with affiliates choosing between personal or program-supplied access.
DevMan first surfaced in April 2025 as an affiliate associated with Qilin, DragonForce, Apos, and RansomHub before launching its own independent RaaS brand. Vectra AI observed in October 2025 that the locker shares unmistakable code lineage with DragonForce. In an interview with researcher Jon DiMaggio that same month, the threat actor admitted prior work with Conti and claimed to have built a "specialized SCADA locker" targeting an unnamed gas company, designed to push industrial control systems past their operating parameters until hardware failure. The Israel National Cyber Directorate noted DevMan's unusually high-profile online presence, posting updates and attack write-ups in English and occasionally Russian, often bragging about intrusion methods. Investigators tracking the group's infrastructure can use a WHOIS lookup to map related domains, while a port scanner helps identify exposed services on affiliate-controlled hosts.
The operation suffered a significant blow in June 2025 when a whistleblower using the handle GangExposed publicly doxxed several operator identities, causing some affiliates to abandon the platform. DevMan alleged that GangExposed attempted to extort them for 0.3 to 1 Bitcoin during Telegram exchanges. Despite the setback, the group persisted, and in January 2026 released version 3 of its affiliate portal with structured victim records and expanded management features. According to Ransomware.Live statistics, DevMan has claimed 184 victims overall, with no new listings after February 4, 2026. Nearly 50 of those victims are based in the United States, concentrated across technology, healthcare, financial services, professional services, and government sectors. Security teams monitoring for affiliate activity can run a VPN/proxy detector against suspicious traffic sources to flag anonymized connections that may indicate operator or affiliate infrastructure.