← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

DevMan RaaS Operates Centralized Portal for Payload Builds and Victim Management

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • DevMan RaaS uses a web portal for affiliates.
  • Portal centralizes payload building, victim management, and payouts.
  • DevMan previously operated as an affiliate for other RaaS groups.
  • The group claimed 184 victims, with no new victims since February 2026.

Centralized RaaS Operations

The DevMan ransomware-as-a-service (RaaS) scheme maintains a dedicated web platform that provides affiliates with tools for building payloads, overseeing earnings, and managing victim interactions. This operation is being tracked by the Swiss cybersecurity company PRODAFT under the name Funky Mantis.

Portal Functionality

The DevMan portal combines several critical functions, including build generation, finance management, victim chat, support, victim records, team coordination, and payout processing. It also integrates access brokerage with ransomware deployment, offering country-specific networks and imposing strict completion windows for affiliates.

DevMan's Evolution and Origins

DevMan first appeared in April 2025 as an affiliate for other RaaS groups like Qilin, DragonForce, Apos, and RansomHub, before establishing its own RaaS operation. Analysis by Vectra AI in October 2025 indicated that DevMan's ransomware shares a lineage with DragonForce, suggesting a common origin or shared code base.

Targeting and Public Presence

DevMan has claimed to have developed a specialized SCADA locker designed to target industrial control systems, aiming to inflict physical damage beyond data encryption. The group maintains a high-profile online presence, frequently posting updates and achievements in English and Russian, sometimes detailing their attack methodologies.

Operational Challenges and Victim Count

In June 2025, DevMan's operations faced disruption when a whistleblower, GangExposed, publicly revealed operator identities, leading some affiliates to leave the group. DevMan alleged that GangExposed attempted extortion. According to Ransomware.Live, DevMan has claimed 184 victims, with no new victims reported after February 4, 2026.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~12 min · 11 stories · Jul 25

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The DevMan ransomware-as-a-service (RaaS) scheme utilizes a dedicated web portal for affiliates to build payloads, manage victims, and handle payouts. This centralized platform, tracked by PRODAFT as Funky Mantis, integrates various functions from build generation to victim chat and financial management, indicating a structured and sophisticated operation.