The DevMan ransomware-as-a-service (RaaS) scheme maintains a dedicated web platform that provides affiliates with tools for building payloads, overseeing earnings, and managing victim interactions. This operation is being tracked by the Swiss cybersecurity company PRODAFT under the name Funky Mantis.
The DevMan portal combines several critical functions, including build generation, finance management, victim chat, support, victim records, team coordination, and payout processing. It also integrates access brokerage with ransomware deployment, offering country-specific networks and imposing strict completion windows for affiliates.
DevMan first appeared in April 2025 as an affiliate for other RaaS groups like Qilin, DragonForce, Apos, and RansomHub, before establishing its own RaaS operation. Analysis by Vectra AI in October 2025 indicated that DevMan's ransomware shares a lineage with DragonForce, suggesting a common origin or shared code base.
DevMan has claimed to have developed a specialized SCADA locker designed to target industrial control systems, aiming to inflict physical damage beyond data encryption. The group maintains a high-profile online presence, frequently posting updates and achievements in English and Russian, sometimes detailing their attack methodologies.
In June 2025, DevMan's operations faced disruption when a whistleblower, GangExposed, publicly revealed operator identities, leading some affiliates to leave the group. DevMan alleged that GangExposed attempted extortion. According to Ransomware.Live, DevMan has claimed 184 victims, with no new victims reported after February 4, 2026.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The DevMan ransomware-as-a-service (RaaS) scheme utilizes a dedicated web portal for affiliates to build payloads, manage victims, and handle payouts. This centralized platform, tracked by PRODAFT as Funky Mantis, integrates various functions from build generation to victim chat and financial management, indicating a structured and sophisticated operation.