Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2053+ Articles
153+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
NEWS

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

PRODAFT has published detailed analysis of the DevMan ransomware-as-a-service operation, revealing a professional-grade affiliate portal with payload builders, victim lifecycle management, churn requirements, and an 80/20 revenue split — plus a disturbing Huntress insider leak angle.

Dylan H.

News Desk

July 25, 2026
4 min read

Swiss cybersecurity firm PRODAFT has published a detailed analysis of DevMan, a ransomware-as-a-service (RaaS) operation the company tracks internally as Funky Mantis. The report reveals a professional, centrally administered criminal platform with affiliate governance policies, structured payout systems, and purpose-built tools for every stage of a ransomware attack — all wrapped in a slick web portal that rivals legitimate SaaS products.

From Qilin Affiliate to Independent Operation

DevMan emerged in April 2025 as a Qilin affiliate before breaking off to launch its own RaaS infrastructure. Vectra AI researchers note "unmistakably DragonForce" ancestry with Conti connections, placing DevMan in the lineage of some of the most sophisticated ransomware organizations ever documented.

The operation reached Version 3 of its portal in January 2026, introducing expanded capabilities and more structured affiliate management.

What the Portal Offers

The DevMan affiliate portal is a full-featured criminal administration platform. Affiliates gain access to:

Payload Builder

  • Generate customized ransomware binaries for Windows, ESXi, and Linux targets
  • Per-victim build options including encryption scope and behavioral flags
  • A separate SCADA-specific encryptor for industrial control system attacks

Victim Lifecycle Management

  • Structured victim records tracking the full attack lifecycle from initial access to ransom payment
  • Deadline tracking and real-time revenue monitoring
  • Shared access across administrators with role separation
  • Chat interface for victim negotiation

Affiliate Governance

  • 80/20 revenue split — affiliates keep 80% of ransom payments
  • Ransom deposits automatically split to dual wallets (affiliate + program operator)
  • Churn requirement: affiliates must produce their first victim within one month or lose membership
  • Administrators can take over victim negotiations if affiliates behave inappropriately
  • Team creation with invitation controls and approval requirements

This level of operational structure — governance policies, churn requirements, admin oversight — mirrors the management systems of legitimate software businesses.

Technical Specifications

DevMan's encryptor uses ChaCha20-Poly1305 authenticated encryption:

File SizeEncryption Strategy
<= 3 MBFull encryption
> 3 MBPartial encryption (1 MB chunks every 51 MB)

Post-compromise capabilities include privilege escalation, security control impairment, process and service termination, shadow copy deletion, event log clearing, lateral movement, and multi-threaded encryption for speed.

Targeting Policies

DevMan's rules of engagement reveal calculated targeting decisions:

Prohibited:

  • Organizations in CIS nations and Serbia
  • Child healthcare facilities and data involving minors

Explicitly encouraged:

  • Critical infrastructure — a dedicated SCADA encryptor is available for industrial system attacks

The explicit SCADA targeting policy distinguishes DevMan from operators who prohibit critical infrastructure attacks as a liability-avoidance measure.

Scale and Impact

PRODAFT's research documents 184 claimed victims, with approximately 50 in the United States concentrated in technology, healthcare, finance, and government sectors. Victim claim activity appears to have stopped after February 4, 2026, though this may reflect operational security changes rather than cessation of activity.

The Huntress Insider Leak

The most striking element of PRODAFT's report involves a Huntress employee who allegedly forwarded FBI communications about the DevMan investigation to the threat actors — including the names of FBI agents involved. Former Huntress employee Ben Folland characterized the behavior as meeting the definition of an insider threat, comparable to warning a fraud suspect about an ongoing police investigation.

The incident, if confirmed, represents a significant operational security breach that may have impacted law enforcement efforts against the group and endangered FBI personnel.

Key Takeaways

  • DevMan (Funky Mantis) operates a SaaS-grade criminal affiliate platform with governance, churn requirements, and structured payouts
  • 184 claimed victims — primarily U.S. technology, healthcare, finance, and government
  • SCADA and critical infrastructure explicitly targeted — a dedicated encryptor is available
  • ChaCha20-Poly1305 encryption with partial-encryption strategy for large files (speed-optimized)
  • Alleged Huntress insider forwarded FBI communications including agent names to the threat actors
  • The 80/20 affiliate split and one-month churn requirement indicate a mature, revenue-focused criminal operation

References

  • The Hacker News — DevMan RaaS Portal Centralizes Payload Builds
  • PRODAFT — Funky Mantis Research
#Ransomware#DevMan#RaaS#PRODAFT#Cybercrime#Funky Mantis#ChaCha20

Related Articles

How Ransomware Syndicates Weaponize Corporate-Style Organization

From outsourced labor to tiered pricing models, today's top ransomware groups operate less like rogue hackers and more like Fortune 500 companies — with...

5 min read

Europe Evolves Into Ransomware's Favorite Region

New research from Black Kite shows ransomware attacks against European organizations surged 55% in the first four months of 2026 compared to the same...

3 min read

INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023

Cybersecurity researchers have charted the evolution of INC ransomware from a nascent RaaS operation to one of the most prolific cybercrime groups in...

3 min read
Back to all News