DevMan Ransomware-as-a-Service: Advanced Operations, SCADA Threats, and Insider Allegations
The **DevMan** ransomware-as-a-service (RaaS) operation is employing a sophisticated web platform for affiliates, offering tools for payload generation, victim management, and financial oversight. Tracked as **Funky Mantis** by **PRODAFT**, the group has also been linked to specialized **SCADA** locker development and faces accusations of insider communication with law enforcement.
# DevMan Ransomware-as-a-Service: Advanced Operations, SCADA Threats, and Insider Allegations
Operators of the **DevMan** ransomware-as-a-service (RaaS) scheme are leveraging a dedicated web platform, providing affiliates with comprehensive tools to build payloads, monitor earnings, and manage victims. This centrally administered RaaS operation is being tracked by Swiss cybersecurity company **PRODAFT** under the name **Funky Mantis**.
## A Sophisticated Affiliate Platform
**PRODAFT**'s extensive report details a portal that integrates build generation, finance management, victim chat, support, victim records, team collaboration, and payout functions. "The service integrated access brokerage or access distribution with ransomware deployment," the company stated, noting that administrators offered country-specific 'networks' and imposed strict completion windows for affiliates.
**DevMan** first emerged in April 2025, initially as an affiliate for groups like **Qilin**, **DragonForce**, **Apos**, and **RansomHub**, before launching its own RaaS. **Vectra AI** previously highlighted the ransomware's strong lineage to **DragonForce**, noting its "unmistakably DragonForce" DNA.
## Targeting Industrial Control Systems
In an October 2025 interview, **DevMan** claimed to have developed a specialized **SCADA** locker designed to target an unnamed gas company. This malware aimed to inflict physical damage by pushing industrial control systems beyond their operational limits, causing hardware failure rather than just encryption.
The **Israel National Cyber Directorate (INCD)** previously noted **DevMan**'s high-profile online presence, where the group often 'brags' about its achievements and describes attack methodologies in English and Russian.
## Setbacks and Evolution
**DevMan**'s operations faced a setback in June 2025 when a whistleblower, **GangExposed**, publicly doxxed operator identities, leading some affiliates to abandon the group. **DevMan** also alleged extortion attempts by **GangExposed** during Telegram interactions.

According to **Ransomware.Live**, **DevMan** has claimed 184 victims to date, with no new victims reported after February 4, 2026. The U.S. accounts for nearly 50 victims, primarily across technology, healthcare, financial services, professional services, and government sectors.
The affiliate portal has evolved, with version 3 (v3) released in January 2026. This upgrade introduced structured victim records, lifecycle states, team creation, invitation controls, per-victim build options, deadline tracking, revenue fields, and shared operational access. **PRODAFT** interprets this as an effort to formalize affiliate workflows and manage multiple intrusions more efficiently.
## Inside the DevMan Hierarchy
**PRODAFT** has identified five distinct roles within the **DevMan** operations:
* **LARVA-367**: The administrator/owner and central coordinator.
* **LARVA-546**: An access coordinator and alternative contact for network access.
* **LARVA-547**: A senior operator.
* **LARVA-548**: Another senior operator or coordinator.
* **LARVA-550**: An affiliate/operator credited with an installation.
Affiliates are added to a corporate chat after their first victim and assigned an experienced curator. They can be removed after one month without a new victim, and team formation requires curator approval, limiting independent coordination.
The core management can also intervene in conversations if an affiliate acts inappropriately, enforcing operational tempo and protecting revenue. The illicit proceeds follow an 80-20% split, with the v3 platform directing funds to separate affiliate and RaaS program wallets.
## Targeting Policies and Technical Analysis
**DevMan**'s targeting policy permits attacks outside CIS countries and Serbia, excluding CIS consulates and CIS-linked companies. It also encourages attacks against critical infrastructure and instructs affiliates to request separate encryptors for **SCADA** systems. However, the policy forbids attacks on child-related healthcare businesses and the intentional leaking of personal data belonging to minors.
The latest portal version allows affiliates to create lockers for **Windows**, **ESXi**, or **Linux**. Analysis of the **Windows** version reveals functions for privilege checking, security-control impairment, process/service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion. The locker uses **ChaCha20-Poly1305** for encryption, fully encrypting files up to 3 MiB and partially encrypting larger ones.
**PRODAFT** recommends organizations prohibit service and backup accounts from interactive VPN login without documented operational requirements, and use phishing-resistant MFA for remote access and privileged administration. Regularly rotating credentials exposed to VPN appliances, LDAP integrations, scripts, and backup tooling is also crucial.
## Insider Threat Allegations Against Huntress
These disclosures coincide with allegations against security firm **Huntress**. **Ben Folland**, a former **Huntress** employee, accused another analyst of passing communications from U.S. law enforcement to **DevMan**. This incident reportedly occurred in December 2025.
**Huntress** CEO **Kyle Hanslovan** acknowledged "questionable, long-term threat actor communications" between a current threat researcher and a cybercriminal, describing it as "poor judgment." While the disclosure to a threat actor about law enforcement contact was not illegal, it prompted **Huntress** to implement more robust policies, coach teammates on threat actor engagement, and take administrative actions. No evidence of illegal conduct or additional disclosures has been found to date.