"The portal combined build generation, finance, victim chat, support, victim records, teams, and payout functions," PRODAFT said.
How the DevMan RaaS portal operates, according to PRODAFT
Swiss cybersecurity firm PRODAFT identified a centrally administered ransomware-as-a-service (RaaS) operation it is tracking under the name Funky Mantis, run by the DevMan group. The service offers affiliates a single web platform where payload builders, finance controls, victim chat, help desk functions and victim records converge. The administrators integrated access brokerage with ransomware deployment, creating an operational flow that asks whether an affiliate will use personal or program-supplied access, assigns country-specific "networks," and enforces two-to-three-day completion windows for intrusions.
Technical capabilities of the DevMan locker
The portal's v3 release in January 2026 added per-victim build options and shared operational access; affiliates can create lockers for Windows, ESXi, or Linux. PRODAFT's analysis of the Windows builder identified behavior consistent with a full-featured locker: privilege checking for elevated execution, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion. The locker uses ChaCha20-Poly1305 and encrypts files up to and including 3 MiB fully; files larger than that are partially encrypted by processing a 1 MiB chunk every 51 MiB.
Roles, governance, and economics inside DevMan
PRODAFT mapped five distinct roles inside DevMan: LARVA-367 (administrator/owner and central coordinator), LARVA-546 (access coordinator), LARVA-547 and LARVA-548 (senior operators/coordinators), and LARVA-550 (an affiliate credited with an installation). Affiliates are added to corporate chat after producing a first victim and are assigned an experienced curator; they may be removed after one month without a new victim. Team formation and disclosure of program affiliation require curator approval, and core management reserves the right to take over conversations or operations if affiliates fail commitments. The RaaS economics follow an 80-20% split in favor of the affiliate, and v3 rules specify that ransom funds are sent to two wallets: one for the affiliate and one linked to the RaaS program.
Victimology, targeting rules, and public presence
Ransomware.Live statistics show DevMan has claimed 184 victims to date, with no new victims reported after February 4, 2026; nearly 50 victims are located in the U.S. The sectors most frequently targeted are technology, healthcare, financial services, professional services, and government. DevMan's stated targeting policy allows affiliates to strike entities outside the Commonwealth of Independent States (CIS) countries and Serbia, explicitly excludes CIS consulates and CIS-linked companies, and lifted a prior restriction on Saudi Arabia. The policy explicitly encourages attacks against critical infrastructure and instructs affiliates to request a separate encryptor for SCADA systems, while forbidding attacks against child-related healthcare businesses and intentional leaks of personal data belonging to people under 18.
Claims about SCADA capabilities and earlier lineage
In an October 2025 interview with security researcher Jon DiMaggio, DevMan acknowledged working with Conti and claimed it had developed a "specialized SCADA locker" designed to inflict progressive physical damage on an unnamed gas company. Per the threat actor's description, the malware would "push industrial control systems beyond their operating parameters, processors, memory, and thermal limits, forcing systems to ramp up and run hot until hardware failed." Independent analysts tracked DevMan's emergence in April 2025 as an affiliate for Qilin, DragonForce, Apos, and RansomHub before the operation shifted to its own RaaS; Vectra AI noted in October 2025 that the locker's DNA was "unmistakably DragonForce."
Huntress insider-allegation and law enforcement contacts
The disclosure about DevMan coincides with an insider-allegation dispute at security firm Huntress. Former Huntress employee Ben Folland accused another analyst of passing U.S. law enforcement communications to DevMan in December 2025. Huntress CEO Kyle Hanslovan acknowledged "questionable, long-term threat actor communications" by a current researcher and said one exchange disclosed that law enforcement had reached out; Hanslovan characterized that disclosure as "poor judgment" but said it was not illegal. Huntress said it implemented stronger policies, coached teammates, and took administrative actions while continuing its investigation. Folland, however, said the employee forwarded exact FBI communications, including screenshots containing FBI agent names, to the threat actor and refused to cooperate with law enforcement—an action he described as meeting the definition of an insider threat.
What this means for security teams, policymakers, and affected enterprises
- Security teams should note PRODAFT's operational recommendations: prohibit service and backup accounts from interactive VPN login unless a documented operational need exists; require phishing-resistant MFA for remote access and privileged administration; and prioritize rotation of credentials exposed to VPN appliances, LDAP integrations, scripts, and backup tooling—especially secrets that can grant local or domain administrative access.
- Policymakers and law enforcement must reckon with two facts present in the record: a RaaS that formalizes affiliate workflows and a contested disclosure of law-enforcement contact between a private researcher and an actor—both complicating intelligence collection and response.
- Affected enterprises should watch for the v3 feature set—per-victim builds and shared access—that can make single intrusions more easily scaled across affiliates, and take inventory of SCADA and backup access paths given DevMan's explicit instructions around specialized SCADA encryptors.
DevMan's centralized portal and its formalized affiliate governance show a maturing criminal business model: integrated access brokerage, per-victim cryptographic builds, curated affiliate onboarding and an 80-20 payout structure. The combination of technical evolution, a claimed SCADA capability, and an internal dispute over handling of law-enforcement contacts leaves open a concrete question raised by the public record: if DevMan's victim count halted after February 4, 2026, is that a temporary operational pause, fallout from the June 2025 GangExposed doxxing, or the effect of other unseen pressures? The available facts do not answer that, but they do point to where defenders and investigators must focus next: credentials, backup and VPN access, and any channels that let affiliates scale multiple intrusions through a single platform.




