Full Report
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. Swiss cybersecurity company PRODAFT is tracking the centrally administered RaaS operation under the name Funky Mantis. "The portal combined build generation, finance,
Analysis Summary
# Threat Actor: DevMan
## Attribution & Identity
* **Actor Name:** DevMan
* **Tracked As:** Funky Mantis (by PRODAFT)
* **Known Aliases:** Sometimes referred to as "The Gentlemen" (associated lineage).
* **Known Associations:**
* **Conti:** The actor claims historical cooperation with the defunct Conti group.
* **DragonForce:** Analysis indicates the ransomware "DNA" is unmistakably derived from or shared with DragonForce.
* **Prior Affiliate Ties:** Formerly operated as an affiliate for **Qilin**, **DragonForce**, **Apos**, and **RansomHub** before launching a standalone RaaS.
## Activity Summary
DevMan emerged in April 2025 as a multi-ransomware affiliate. By mid-to-late 2025, they transitioned into a Ransomware-as-a-Service (RaaS) operator. Despite a major doxxing incident by a whistleblower ("GangExposed") in June 2025, the group continued operations, launching version 3 of their management portal in January 2026. The group has claimed at least 184 victims, though reporting suggests a pause in activity after February 4, 2026.
## Tactics, Techniques & Procedures
* **RaaS Operations:** Centrally administered portal for payload generation, victim negotiation, and financial tracking.
* **Access Brokerage Integration:** The portal offers country-specific "networks" and access distribution directly to affiliates.
* **Strict Timeframes:** Imposes 2-to-3-day completion windows for affiliates to execute attacks.
* **Double Extortion:** Combination of data encryption and "shaming" via public write-ups and achievement "bragging."
* **Destructive Capabilities:** Claims to possess a "specialized SCADA locker" designed to physically damage industrial hardware by pushing thermal and processor limits until failure.
* **Multi-Role Hierarchy:** Utilizes a structured internal system (LARVA-367 through LARVA-550) overseeing various functions from administration to access coordination and affiliate management.
## Targeting
* **Sectors:** Technology, Healthcare, Financial Services, Professional Services, and Government.
* **Geography:** Primarily the United States (nearly 50 victims), with secondary activity in Russian and English-speaking regions.
* **Victims:** 184 total victims claimed; one unnamed major gas company targeted with SCADA-specific lockers.
## Tools & Infrastructure
* **Malware Families:** DevMan Locker (DragonForce/Conti lineage), specialized SCADA-targeting ransomware.
* **Infrastructure:**
* **DevMan RaaS Portal v3:** A web platform for payload builds, structured victim records, and revenue management.
* **Communication:** Mainly Telegram for coordination and interaction with researchers/whistleblowers.
* **Domains/URLs:**
* hXXps://thehackernews[.]com/2026/07/devman-raas-portal-centralizes-payload.html
* hXXps://catalyst.prodaft[.]com/public/report/funky-mantis-platform-coordination-and-locker-analysis/
* hXXps://analyst1[.]com/devmans-raas-launch-the-affiliate-who-aims-to-become-the-boss/
## Implications
DevMan represents the "professionalization" of the affiliate model, shifting from a mere executor of attacks to a platform provider. Their claim of physical hardware destruction via SCADA-specific malware marks a significant escalation from traditional data encryption to kinetic cyber-physical threats. The centralization of their workflow suggests they are prioritizing operational efficiency and high-volume, managed intrusions.
## Mitigations
* **Industrial Control Systems (ICS) Hardening:** Implement out-of-band monitoring for thermal and processor loads to detect anomalous behavior before hardware failure occurs.
* **Access Management:** Monitor for initial access brokerage activities, specifically looking for the sale of "networks" related to the organization's geographic region.
* **Rapid IR:** Organizations should have an incident response plan capable of acting within the 48-72 hour window specified by the actor's completion requirements.
* **Network Segmentation:** Inhibit lateral movement to prevent ransomware reaching specialized SCADA or OT environments.