Swiss cybersecurity firm PRODAFT has published a detailed analysis of DevMan, a ransomware-as-a-service (RaaS) operation the company tracks internally as Funky Mantis. The report reveals a professional, centrally administered criminal platform with affiliate governance policies, structured payout systems, and purpose-built tools for every stage of a ransomware attack — all wrapped in a slick web portal that rivals legitimate SaaS products.
From Qilin Affiliate to Independent Operation
DevMan emerged in April 2025 as a Qilin affiliate before breaking off to launch its own RaaS infrastructure. Vectra AI researchers note "unmistakably DragonForce" ancestry with Conti connections, placing DevMan in the lineage of some of the most sophisticated ransomware organizations ever documented.
The operation reached Version 3 of its portal in January 2026, introducing expanded capabilities and more structured affiliate management.
What the Portal Offers
The DevMan affiliate portal is a full-featured criminal administration platform. Affiliates gain access to:
Payload Builder
- Generate customized ransomware binaries for Windows, ESXi, and Linux targets
- Per-victim build options including encryption scope and behavioral flags
- A separate SCADA-specific encryptor for industrial control system attacks
Victim Lifecycle Management
- Structured victim records tracking the full attack lifecycle from initial access to ransom payment
- Deadline tracking and real-time revenue monitoring
- Shared access across administrators with role separation
- Chat interface for victim negotiation
Affiliate Governance
- 80/20 revenue split — affiliates keep 80% of ransom payments
- Ransom deposits automatically split to dual wallets (affiliate + program operator)
- Churn requirement: affiliates must produce their first victim within one month or lose membership
- Administrators can take over victim negotiations if affiliates behave inappropriately
- Team creation with invitation controls and approval requirements
This level of operational structure — governance policies, churn requirements, admin oversight — mirrors the management systems of legitimate software businesses.
Technical Specifications
DevMan's encryptor uses ChaCha20-Poly1305 authenticated encryption:
| File Size | Encryption Strategy |
|---|---|
| <= 3 MB | Full encryption |
| > 3 MB | Partial encryption (1 MB chunks every 51 MB) |
Post-compromise capabilities include privilege escalation, security control impairment, process and service termination, shadow copy deletion, event log clearing, lateral movement, and multi-threaded encryption for speed.
Targeting Policies
DevMan's rules of engagement reveal calculated targeting decisions:
Prohibited:
- Organizations in CIS nations and Serbia
- Child healthcare facilities and data involving minors
Explicitly encouraged:
- Critical infrastructure — a dedicated SCADA encryptor is available for industrial system attacks
The explicit SCADA targeting policy distinguishes DevMan from operators who prohibit critical infrastructure attacks as a liability-avoidance measure.
Scale and Impact
PRODAFT's research documents 184 claimed victims, with approximately 50 in the United States concentrated in technology, healthcare, finance, and government sectors. Victim claim activity appears to have stopped after February 4, 2026, though this may reflect operational security changes rather than cessation of activity.
The Huntress Insider Leak
The most striking element of PRODAFT's report involves a Huntress employee who allegedly forwarded FBI communications about the DevMan investigation to the threat actors — including the names of FBI agents involved. Former Huntress employee Ben Folland characterized the behavior as meeting the definition of an insider threat, comparable to warning a fraud suspect about an ongoing police investigation.
The incident, if confirmed, represents a significant operational security breach that may have impacted law enforcement efforts against the group and endangered FBI personnel.
Key Takeaways
- DevMan (Funky Mantis) operates a SaaS-grade criminal affiliate platform with governance, churn requirements, and structured payouts
- 184 claimed victims — primarily U.S. technology, healthcare, finance, and government
- SCADA and critical infrastructure explicitly targeted — a dedicated encryptor is available
- ChaCha20-Poly1305 encryption with partial-encryption strategy for large files (speed-optimized)
- Alleged Huntress insider forwarded FBI communications including agent names to the threat actors
- The 80/20 affiliate split and one-month churn requirement indicate a mature, revenue-focused criminal operation