**DevMan Ransomware-as-a-Service (RaaS): A Comprehensive Analysis**
The digital landscape is constantly evolving, with cyber threats becoming increasingly sophisticated and organized. One of the most significant recent developments in the world of cybercrime is the rise of structured Ransomware-as-a-Service (RaaS) operations. Among these, **DevMan** stands out as a particularly concerning entity. This article delves into the inner workings of the DevMan RaaS platform, codenamed **Funky Mantis** by security researchers, exploring its structure, evolution, and the severe risks it poses to organizations worldwide.
### **The Funky Mantis Platform: A Criminal’s Headquarters**
Swiss cybersecurity firm PRODAFT has been instrumental in tracking the Funky Mantis platform. This is not a simple dark web forum; it is a fully-fledged, centrally administered business portal designed to professionalize ransomware operations. The platform integrates a wide array of functions that mirror legitimate software-as-a-service models, including:
* **Build Generation:** Affiliates can create custom ransomware payloads.
* **Finance & Payouts:** Detailed revenue tracking and automated profit splitting.
* **Victim Management:** A dedicated chat system, support portal, and comprehensive victim records.
* **Access Brokerage:** The platform uniquely integrates access brokerage, allowing affiliates to purchase or use provided credentials for network intrusion.
* **Operational Governance:** Administrators can set deadlines, manage teams, and enforce rules.
This level of sophistication signifies a shift from opportunistic hacking to a managed, industrial-scale approach to cybercrime.
### **Evolution and Technical Capabilities**
DevMan’s journey began in April 2025. Initially, it operated as an affiliate program for other major ransomware groups like Qilin, DragonForce, and RansomHub. However, it quickly evolved into its own RaaS offering. Security analysts note that its underlying code is “unmistakably DragonForce,” indicating a strategic pivot built on a proven, dangerous foundation.
The technical capabilities of the DevMan locker are formidable. It is designed to maximize damage, with allegations that it was used in a targeted attack against a gas company to inflict “progressive physical damage” by pushing industrial control systems beyond their operational limits. Its encryption strategy is also sophisticated, using ChaCha20-Poly1305 and employing a partial encryption method for large files to ensure speed and efficiency. The platform supports deployments across Windows, ESXi, and Linux environments, making it a versatile threat to diverse IT infrastructures.
### **Organizational Structure and Governance**
What makes DevMan truly alarming is its corporate-like structure. PRODAFT has identified five distinct roles within its ecosystem, from the central Administrator (LARVA-367) to Senior Operators and Affiliates. This hierarchy allows for tight control and quality assurance. Affiliates are not independent actors; they are managed, curated, and can even be removed for inactivity. The platform’s v3 update, released in January 2026, further formalized these workflows, moving from simple chat-based coordination to a structured system with team creation, lifetime cycle states, and strict approval processes. This governance model reduces affiliate autonomy but ensures a more controlled and profitable operation for the administrators.
### **Targets and Policies**
DevMan’s targeting policy is broad but calculated. It encourages attacks on entities outside the CIS countries and Serbia, explicitly targets critical infrastructure, and has even lifted previous restrictions on Saudi Arabia. However, there are internal boundaries; the platform forbids affiliates from attacking child-related healthcare businesses or intentionally leaking data of minors. This selective prohibition is less about ethics and more about mitigating legal and reputational risk for the operation itself.
### **Recent Disruptions and Insider Threats**
The operation faced a significant setback in June 2025 when a whistleblower, “GangExposed,” doxxed operator identities. This event caused several affiliates to abandon the operation and was followed by extortion attempts against the DevMan administrators themselves.
Adding a layer of complexity to the threat landscape is the recent insider threat allegation involving security firm Huntress. A former Huntress employee, Ben Folland, accused a current analyst of sharing communications from U.S. law enforcement with the DevMan threat actor. This incident highlights the critical challenge of insider threats and the potential for sensitive intelligence to compromise investigations and aid criminal enterprises.
***
### **FAQ**
**Q1: What is DevMan ransomware?**
DevMan is a Ransomware-as-a-Service (RaaS) operation, also known by the codename Funky Mantis. It is a professionalized cybercrime platform that provides affiliates with the tools, infrastructure, and support needed to launch ransomware attacks in exchange for a share of the profits.
**Q2: Who is behind the name “Funky Mantis”?**
“Funky Mantis” is the name given to the DevMan RaaS operation by the cybersecurity company PRODAFT, which has been actively tracking the platform’s activities and structure.
**Q3: What makes the DevMan platform different from other ransomware operations?**
Unlike many ad-hoc ransomware campaigns, DevMan operates a sophisticated, centralized portal that functions like a legitimate SaaS model. It offers build generation, integrated finance and payout systems, victim chat and support, access brokerage, and strict operational governance with defined roles (like LARVA codes), making it a highly organized criminal business.
**Q4: What types of systems does the DevMan ransomware target?**
The DevMan ransomware is designed to be versatile, with capabilities for Windows, Linux, and ESXi systems. It has also been linked to attacks targeting critical infrastructure, including SCADA systems, with the alleged intent of causing physical damage.
**Q5: Has the DevMan operation been disrupted?**
Yes. The operation suffered a significant blow in June 2025 when a whistleblower doxxed the identities of its operators. This led to a loss of trust and caused some affiliates to abandon the operation. The platform has since released a more advanced version (v3) to rebuild and formalize its structure.
**Q6: What is the “insider threat” related to DevMan?**
An insider threat allegation emerged involving Huntress, a cybersecurity firm. A former employee was accused of sharing sensitive communications from U.S. law enforcement about the DevMan investigation with the threat actor itself, a severe breach of trust that reportedly meets the definition of an insider threat.
***
### **Conclusion**
The DevMan ransomware operation represents a new and dangerous evolution in cybercrime. By implementing a professionalized, platform-based RaaS model, it has lowered the barrier to entry for devastating cyberattacks while maintaining a high degree of control and profitability. Its sophisticated platform, diverse targeting strategy, and recent real-world impacts underscore its lethality. The emergence of insider threats further complicates the defense against such operations. Combating this level of organized cybercrime requires a multi-faceted approach, including improved insider threat programs, robust international cooperation, and continued vigilance from organizations of all sizes. The Funky Mantis is not just a malware; it is a blueprint for the future of ransomware gangs.



