Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
DevMan RaaS Centralizes Cyber Operations and Affiliations

DevMan RaaS Centralizes Cyber Operations and Affiliations

Posted on July 25, 2026 By CWS

The DevMan ransomware-as-a-service (RaaS) operation is utilizing a specialized online portal to streamline the creation of payloads, monitor affiliate earnings, and manage victim interactions. This operation, known as Funky Mantis, is being closely monitored by Swiss cybersecurity firm PRODAFT.

The Multifunctional Portal

According to a detailed report shared with The Hacker News, the DevMan platform integrates several functions including build generation, financial management, victim communication, support services, and team coordination. It combines access brokerage with ransomware deployment, offering country-specific networks and presenting affiliates with options for using personal or provided access, all within a strict timeline.

Emerging in April 2025, DevMan started as an affiliate for Qilin and others before transitioning into its own RaaS framework. Its ransomware shares lineage with the DragonForce, as noted by Vectra AI. DevMan has also claimed to develop a specialized SCADA locker aimed at inflicting physical damage beyond encryption.

Operational Challenges and Portal Evolution

In June 2025, DevMan faced a significant challenge when GangExposed, a whistleblower, publicized the identities of its operators, causing some affiliates to defect. GangExposed also attempted to extort DevMan for Bitcoin during their interactions on Telegram.

Despite these setbacks, DevMan’s portal has evolved. The latest version, released in January 2026, includes advanced features for managing victim records and affiliate workflows. This shift aims to formalize operations and improve coordination among affiliates.

PRODAFT has identified various roles within the operation, indicating a structured hierarchy. Affiliates are integrated into the system after proving their capability, with oversight ensuring compliance and performance.

Security and Insider Threats

A recent disclosure has alleged insider threats within the security firm Huntress, involving communication between a researcher and DevMan. According to ex-employee Ben Folland, an analyst at Huntress reportedly shared information from U.S. law enforcement with DevMan, raising concerns about insider threats.

Huntress CEO Kyle Hanslovan acknowledged the incident, emphasizing enhanced policies and administrative actions to prevent future occurrences. However, Folland criticized the handling of the situation, arguing it constitutes a significant breach of trust.

This incident highlights the complexities of cybersecurity operations and the challenges posed by potential insider threats. As investigations continue, the industry is reminded of the critical need for robust security protocols and vigilant monitoring.

The Hacker News Tags:affiliate management, cyber operations, cyber threats, Cybersecurity, DevMan, FBI, Funky Mantis, GangExposed, Huntress, insider threat, PRODAFT, RaaS, Ransomware, SCADA locker

Post navigation

Previous Post: Cl0p Ransomware Exploits PTC Software Vulnerabilities
Next Post: Researcher Reveals Potential AI Model Jailbreak Technique

Related Posts

Hackers Exploit Samsung MagicINFO, GeoVision IoT Flaws to Deploy Mirai Botnet Hackers Exploit Samsung MagicINFO, GeoVision IoT Flaws to Deploy Mirai Botnet The Hacker News
RondoDox Exploits Unpatched XWiki Servers to Pull More Devices Into Its Botnet RondoDox Exploits Unpatched XWiki Servers to Pull More Devices Into Its Botnet The Hacker News
North Korea-Linked Hackers Steal .02 Billion in 2025, Leading Global Crypto Theft North Korea-Linked Hackers Steal $2.02 Billion in 2025, Leading Global Crypto Theft The Hacker News
North Korean Hackers Exploit Developer Tools for Cyber Attacks North Korean Hackers Exploit Developer Tools for Cyber Attacks The Hacker News
Microsoft Unveils Tool to Detect AI Model Backdoors Microsoft Unveils Tool to Detect AI Model Backdoors The Hacker News
AI Agents Act Like Employees With Root Access—Here’s How to Regain Control AI Agents Act Like Employees With Root Access—Here’s How to Regain Control The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Researcher Reveals Potential AI Model Jailbreak Technique
  • DevMan RaaS Centralizes Cyber Operations and Affiliations
  • Cl0p Ransomware Exploits PTC Software Vulnerabilities
  • Phishing Threats Evolve to Real-Time Insurance Account Hijacking
  • Fastjson Vulnerability Exploited in Active Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Researcher Reveals Potential AI Model Jailbreak Technique
  • DevMan RaaS Centralizes Cyber Operations and Affiliations
  • Cl0p Ransomware Exploits PTC Software Vulnerabilities
  • Phishing Threats Evolve to Real-Time Insurance Account Hijacking
  • Fastjson Vulnerability Exploited in Active Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark