DevMan RaaS Portal Streamlines Operations for Ransomware Affiliates
The DevMan ransomware-as-a-service operation, tracked as Funky Mantis, utilizes a sophisticated web portal to centralize payload generation, victim management, and affiliate payouts, enhancing operational efficiency.

The DevMan ransomware-as-a-service (RaaS) operation has established a dedicated web portal designed to streamline its illicit activities, offering affiliates a centralized platform for generating custom payloads, managing victim data, and tracking their earnings. Cybersecurity firm PRODAFT, which tracks the operation as Funky Mantis, detailed the portal's comprehensive features in a recent report.
The portal integrates crucial functions for RaaS operations, including build generation, financial management, victim communication channels, support services, victim record-keeping, team coordination, and payout processing. PRODAFT noted that the service effectively combines access brokerage with ransomware deployment, with administrators offering country-specific network access and imposing strict completion timelines of two to three days.
DevMan initially emerged in April 2025, serving as an affiliate for other ransomware operations like Qilin, DragonForce, Apos, and RansomHub, before launching its own RaaS platform. Security researchers have identified strong lineage to the DragonForce ransomware, with one analysis noting its "unmistakably DragonForce" DNA. In a previous interview, DevMan acknowledged ties to the Conti group and claimed to have developed a specialized SCADA locker capable of inflicting physical damage beyond simple data encryption, designed to push industrial control systems beyond their operational limits until hardware failure.
The threat actor has maintained a significant online presence, frequently sharing updates and statements in English and Russian, often boasting about their operational successes and detailing their attack methodologies. However, the operation faced a setback in June 2025 when a whistleblower known as GangExposed publicly revealed operator identities, leading some affiliates to abandon the service. DevMan also alleged that GangExposed attempted to extort them for cryptocurrency.
According to statistics from Ransomware.Live, DevMan has claimed 184 victims to date, with the last reported victim activity occurring on February 4, 2026. The majority of victims are located in the United States, with the technology, healthcare, financial services, professional services, and government sectors being the most frequently targeted.
The affiliate portal has undergone significant evolution, with version 3 (v3) released in January 2026 introducing enhanced features. These include support for structured victim records, lifecycle states, team creation with invitation controls, per-victim build options, deadline tracking, revenue fields, and shared operational access. This progression signifies a move towards formalizing affiliate workflows and managing multiple intrusions through a unified platform, reducing reliance on chat-based coordination.
PRODAFT identified five distinct roles within DevMan's structure: Administrator/owner, Access coordinator, Senior operator, and Affiliate/operator. Affiliates are integrated into corporate chats after successfully compromising a victim and are assigned a curator. Failure to secure a new victim within a month can lead to removal. Team formation and public association with the service require curator approval, limiting affiliate autonomy and fostering centralized control.
The revenue-sharing model typically involves an 80-20% split between the affiliate and the RaaS program, with ransom payments directed to separate wallets. DevMan's targeting policy permits attacks outside CIS countries and Serbia, excluding CIS consulates and companies, while lifting a previous restriction on Saudi Arabia. The group actively encourages attacks against critical infrastructure and provides specialized encryptors for SCADA systems. However, they prohibit attacks against child-related healthcare businesses and the intentional leaking of personal data belonging to minors.