The DevMan ransomware-as-a-service (RaaS) operation is utilizing a specialized online portal to streamline the creation of payloads, monitor affiliate earnings, and manage victim interactions. This operation, known as Funky Mantis, is being closely monitored by Swiss cybersecurity firm PRODAFT.
The Multifunctional Portal
According to a detailed report shared with The Hacker News, the DevMan platform integrates several functions including build generation, financial management, victim communication, support services, and team coordination. It combines access brokerage with ransomware deployment, offering country-specific networks and presenting affiliates with options for using personal or provided access, all within a strict timeline.
Emerging in April 2025, DevMan started as an affiliate for Qilin and others before transitioning into its own RaaS framework. Its ransomware shares lineage with the DragonForce, as noted by Vectra AI. DevMan has also claimed to develop a specialized SCADA locker aimed at inflicting physical damage beyond encryption.
Operational Challenges and Portal Evolution
In June 2025, DevMan faced a significant challenge when GangExposed, a whistleblower, publicized the identities of its operators, causing some affiliates to defect. GangExposed also attempted to extort DevMan for Bitcoin during their interactions on Telegram.
Despite these setbacks, DevMan’s portal has evolved. The latest version, released in January 2026, includes advanced features for managing victim records and affiliate workflows. This shift aims to formalize operations and improve coordination among affiliates.
PRODAFT has identified various roles within the operation, indicating a structured hierarchy. Affiliates are integrated into the system after proving their capability, with oversight ensuring compliance and performance.
Security and Insider Threats
A recent disclosure has alleged insider threats within the security firm Huntress, involving communication between a researcher and DevMan. According to ex-employee Ben Folland, an analyst at Huntress reportedly shared information from U.S. law enforcement with DevMan, raising concerns about insider threats.
Huntress CEO Kyle Hanslovan acknowledged the incident, emphasizing enhanced policies and administrative actions to prevent future occurrences. However, Folland criticized the handling of the situation, arguing it constitutes a significant breach of trust.
This incident highlights the complexities of cybersecurity operations and the challenges posed by potential insider threats. As investigations continue, the industry is reminded of the critical need for robust security protocols and vigilant monitoring.
