Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
DevMan RaaS Centralizes Cyber Operations and Affiliations

DevMan RaaS Centralizes Cyber Operations and Affiliations

Posted on July 25, 2026 By CWS

The DevMan ransomware-as-a-service (RaaS) operation is utilizing a specialized online portal to streamline the creation of payloads, monitor affiliate earnings, and manage victim interactions. This operation, known as Funky Mantis, is being closely monitored by Swiss cybersecurity firm PRODAFT.

The Multifunctional Portal

According to a detailed report shared with The Hacker News, the DevMan platform integrates several functions including build generation, financial management, victim communication, support services, and team coordination. It combines access brokerage with ransomware deployment, offering country-specific networks and presenting affiliates with options for using personal or provided access, all within a strict timeline.

Emerging in April 2025, DevMan started as an affiliate for Qilin and others before transitioning into its own RaaS framework. Its ransomware shares lineage with the DragonForce, as noted by Vectra AI. DevMan has also claimed to develop a specialized SCADA locker aimed at inflicting physical damage beyond encryption.

Operational Challenges and Portal Evolution

In June 2025, DevMan faced a significant challenge when GangExposed, a whistleblower, publicized the identities of its operators, causing some affiliates to defect. GangExposed also attempted to extort DevMan for Bitcoin during their interactions on Telegram.

Despite these setbacks, DevMan’s portal has evolved. The latest version, released in January 2026, includes advanced features for managing victim records and affiliate workflows. This shift aims to formalize operations and improve coordination among affiliates.

PRODAFT has identified various roles within the operation, indicating a structured hierarchy. Affiliates are integrated into the system after proving their capability, with oversight ensuring compliance and performance.

Security and Insider Threats

A recent disclosure has alleged insider threats within the security firm Huntress, involving communication between a researcher and DevMan. According to ex-employee Ben Folland, an analyst at Huntress reportedly shared information from U.S. law enforcement with DevMan, raising concerns about insider threats.

Huntress CEO Kyle Hanslovan acknowledged the incident, emphasizing enhanced policies and administrative actions to prevent future occurrences. However, Folland criticized the handling of the situation, arguing it constitutes a significant breach of trust.

This incident highlights the complexities of cybersecurity operations and the challenges posed by potential insider threats. As investigations continue, the industry is reminded of the critical need for robust security protocols and vigilant monitoring.

The Hacker News Tags:affiliate management, cyber operations, cyber threats, Cybersecurity, DevMan, FBI, Funky Mantis, GangExposed, Huntress, insider threat, PRODAFT, RaaS, Ransomware, SCADA locker

Post navigation

Previous Post: Cl0p Ransomware Exploits PTC Software Vulnerabilities
Next Post: Researcher Reveals Potential AI Model Jailbreak Technique

Related Posts

How to Address the Expanding Security Risk How to Address the Expanding Security Risk The Hacker News
Google Fixes Antigravity IDE Vulnerability Allowing Code Execution Google Fixes Antigravity IDE Vulnerability Allowing Code Execution The Hacker News
Bitfinex Hack Convict Ilya Lichtenstein Released Early Under U.S. First Step Act Bitfinex Hack Convict Ilya Lichtenstein Released Early Under U.S. First Step Act The Hacker News
Microsoft Teams Bugs Let Attackers Impersonate Colleagues and Edit Messages Unnoticed Microsoft Teams Bugs Let Attackers Impersonate Colleagues and Edit Messages Unnoticed The Hacker News
Security Challenges Posed by AI-Driven Apps Exposed Security Challenges Posed by AI-Driven Apps Exposed The Hacker News
ServiceNow Flaw CVE-2025-3648 Could Lead to Data Exposure via Misconfigured ACLs ServiceNow Flaw CVE-2025-3648 Could Lead to Data Exposure via Misconfigured ACLs The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical LiteLLM Vulnerability Risks Cloud Security
  • Fraudulent Apps Exploit Google Play’s Early Access Program
  • Critical Check Point VPN Certificate Flaws Patched
  • Critical Vulnerabilities in Check Point VPN Fixed
  • NetScaler Flaw Exploited in Cyberattacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical LiteLLM Vulnerability Risks Cloud Security
  • Fraudulent Apps Exploit Google Play’s Early Access Program
  • Critical Check Point VPN Certificate Flaws Patched
  • Critical Vulnerabilities in Check Point VPN Fixed
  • NetScaler Flaw Exploited in Cyberattacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark