The developers behind the DevMan ransomware-as-a-service (RaaS) platform have set up a dedicated web interface that empowers affiliates to create malware, monitor profits, and oversee victim-related activities.
PRODAFT, a cybersecurity firm based in Switzerland, has been monitoring the activities of this centrally managed RaaS operation, known as Funky Mantis.
According to PRODAFT’s detailed report, the platform offers a wide range of functionalities such as generating payloads, managing finances, communicating with victims, providing support, keeping records of victims, forming teams, and facilitating payouts.
The service also includes features for access brokerage and ransomware deployment, allowing administrators to tailor attacks based on specific regions, access types, and completion timelines.
Initial analyses indicate that DevMan emerged as an affiliate for other ransomware groups before branching out into its own RaaS operation. The ransomware’s origins can be traced back to DragonForce, a well-known malware family.
In an interview conducted in October 2025, DevMan revealed its collaboration with Conti and its development of a specialized SCADA locker designed to target a gas company by causing physical damage in addition to encrypting data.
The threat actor behind DevMan maintains a prominent online presence, frequently sharing updates and achievements in English and occasionally in Russian, as noted by the Israel National Cyber Directorate (INCD).
DevMan faced setbacks in June 2025 when a whistleblower exposed the identities of the operators, leading to some affiliates leaving the operation. The group also claimed that the whistleblower attempted to extort them for Bitcoin during interactions on Telegram.

As per data from Ransomware.Live, DevMan has targeted 184 victims thus far, with a majority of them located in the U.S. Industries such as technology, healthcare, finance, professional services, and government have been the primary targets.
The affiliate portal associated with DevMan has undergone significant updates, with the latest version (v3) offering enhanced features for managing victim records, team collaboration, deadline tracking, and revenue allocation.
PRODAFT has identified five key roles within the DevMan operations, each responsible for different aspects of the ransomware deployment and management.
- LARVA-367 – Administrator and central coordinator
- LARVA-546 – Access coordinator
- LARVA-547 – Senior operator
- LARVA-548 – Senior operator or coordinator
- LARVA-550 – Affiliate/operator credited for specific installations
Affiliates are closely monitored and guided by experienced curators, with strict rules in place for team formation and program affiliation disclosure. The management retains control over conversations and revenue distribution to ensure operational efficiency.
DevMan’s revenue-sharing model allocates 80% of the extortion profits to the affiliate, with the remaining 20% going to the RaaS program. The platform’s policies outline specific targeting guidelines and restrictions, emphasizing attacks on critical infrastructure while prohibiting certain types of targets.
The latest version of the portal enables affiliates to create custom lockers for different operating systems, with advanced features for file encryption, privilege escalation, lateral movement, and anti-forensic measures.
Organizations are advised to implement strict security measures to mitigate the risk of ransomware attacks, including restricting VPN access for service accounts and enforcing multi-factor authentication for privileged accounts.
Huntress Faces Insider Threat Allegations
Recent allegations have surfaced regarding a former employee of Huntress accusing a current analyst of sharing sensitive information with DevMan. The incident, which occurred in December 2025, raised concerns about insider threats within the cybersecurity community.
In response to the allegations, Huntress CEO Kyle Hanslovan acknowledged the communications between the analyst and the threat actor, describing it as a lapse in judgment. The company has since implemented stricter policies and measures to prevent similar incidents in the future.
The ex-employee, however, maintains that the actions of the analyst constitute an insider threat, pointing out the risks associated with sharing law enforcement communications with cybercriminals.
The ongoing investigation by Huntress aims to uncover any additional breaches of conduct and ensure the security of sensitive information within the organization.

