HomeMalware & ThreatsDevMan RaaS Portal Streamlines Payload Builds, Victim Management, and Affiliate Payouts

DevMan RaaS Portal Streamlines Payload Builds, Victim Management, and Affiliate Payouts

Published on

spot_img

DevMan Ransomware-as-a-Service Platform: Unveiling the Mechanics of a Complex Cybercrime Operation

The landscape of cybercrime has evolved with the emergence of the DevMan ransomware-as-a-service (RaaS) operation, a product of sophisticated criminal collaboration that exploits vulnerabilities while providing affiliates with an organized framework. Swiss cybersecurity firm PRODAFT recently reported that the operators of DevMan have established a dedicated web platform that allows affiliates to create malicious payloads, oversee their earnings, and effectively manage all aspects associated with their victims. This new layer of professionalism within cybercrime signifies a worrying trend in cybersecurity.

The operation, which goes by the name "Funky Mantis," has attracted attention for its well-structured affiliate management system. As highlighted in PRODAFT’s comprehensive report, the platform offers functionalities that integrate everything from builder generation, finance tracking, victim interaction, and administrative support—an amalgamation of features that showcases a high degree of organization typically seen in legitimate businesses, albeit in an illegal context. PRODAFT detailed how the service incorporates access brokerage or distribution alongside ransomware deployment, emphasizing its role as a central hub for affiliates engaging in nefarious activities.

DevMan made its debut in April 2025, initially partnering as an affiliate for established ransomware services like Qilin, DragonForce, Apos, and RansomHub before branching off into its own RaaS operation. Security analysts at Vectra AI have pointed out the unmistakable lineage of the DevMan lockers to DragonForce, exposing the shifting dynamics and rebranding often seen within the cybercriminal underground. This evolution indicates that existing criminal enterprises continually adapt and morph, creating an intricate web of threat actors that can be surprisingly resilient.

One particularly alarming aspect of DevMan’s activities is its ambition to escalate threats beyond data encryption. Researcher Jon DiMaggio reported on the group’s acknowledgment of its collaboration with notorious groups like Conti, hinting at the development of specialized malware aimed at targeting industrial systems—specifically, those responsible for running gas operations. Such designs are not merely intended to extract financial ransom; they are potentially hazardous, capable of causing physical damage to operational equipment.

The Israel National Cyber Directorate (INCD) commented on DevMan’s audacious online presence, noting its brazen self-promotion through updates and claims of successful attacks, often communicated in English and sporadically in Russian. This proclivity for bragging among cybercriminals indicates a desire for recognition and fearlessness stemming from the perceived anonymity that the dark web provides.

However, the operation faced a setback in June 2025 when a whistleblower known as GangExposed publicly revealed the identities of several DevMan operators. This disclosure led to a significant attrition rate among affiliates, with some choosing to distance themselves from the operation fearing potential legal repercussions. Reports indicate that GangExposed even attempted to extort DevMan operators, demanding 0.3 to 1 Bitcoin, adding to the chaotic nature of the criminal ecosystem.

Data from Ransomware.Live underscores the extent of DevMan’s impact, claiming 184 victims since its inception. Nearly fifty of these are reported to be located in the U.S., with sectors like technology, healthcare, finance, and government being particularly vulnerable. This highlights an alarming intersection of cybercrime with critical infrastructure sectors, raising essential questions about national security.

The affiliate portal of DevMan has seen upgrades, with the release of version three (v3) in January 2026, enhancing functionalities like structured victim records and team formation capabilities. These modifications reflect an effort to streamline processes and emphasize coordination among affiliates—signaling a shift towards a more organized structure within the criminal enterprise.

Within the DevMan operations, five distinct roles have been identified, ranging from the administrator to senior operators and affiliates, each with specific duties that enhance operational efficiency. Affiliates are seamlessly integrated into a corporate chat following their first victim, monitored by seasoned curators, which reinforces control and minimizes independent decision-making—a tactic aimed at safeguarding revenue and ensuring loyalty.

Financially, the scheme operates on an 80-20 profit-sharing model post-extortion, with the ransom distributed between the affiliates and the RaaS framework. Furthermore, the group’s targeting policy underscores its reliance on a global strategy, encouraging attacks on entities outside specific regions while restricting operations in others, reflecting an evolving, calculated approach to identify potential victims.

The portal allows affiliates to generate malicious lockers for various operating systems, enhancing their ability to execute attacks without raising alarms. As organizations increasingly face threats from sophisticated RaaS operations like DevMan, proactive measures are crucial. Cybersecurity experts recommend prohibiting interactive VPN logins for sensitive accounts and implementing multi-factor authentication (MFA) to strengthen defenses against such attacks.

The broader implications of DevMan’s operations are further muddled by ongoing insider threat allegations involving a former employee of security firm Huntress, who is accused of sharing sensitive information with cybercriminals. This scenario raises significant ethical and operational questions within the cybersecurity community regarding the boundaries of cooperation with threat actors and the responsibilities of industry professionals.

In conclusion, the emergence of the DevMan RaaS platform encapsulates a broader trend in cybercrime, where enhanced organization and scalability allow for an intricate interplay of criminal activity that threatens various sectors. As the threat landscape grows increasingly complex, continuous vigilance and strategic responses will be pivotal in mitigating the risks posed by such sophisticated cybercriminal enterprises.

Source link

Latest articles

Hackers Exploit Industrial PLCs and Manipulate HMI Displays to Conceal Attacks

Title: Increasing Threat from Iranian Cyber Actors: Updated Advisory Highlights Risks to U.S. Critical...

South Korea Diplomatic Academy Experiences Data Breach

Significant Data Breach at South Korea's Diplomatic Academy: Personal Information Compromised In a troubling revelation,...

SBOM/CVE: The Shield in Cyber Warfare

We Are Conducting Security Drills for the Wrong Catastrophe: Understanding Cyber Threats Beyond "Duck...

Phantom Stealer Campaign Employs JavaScript and PowerShell to Theft Browser Credentials

Phishing Campaign Unveils Advanced Malware Delivery System A sophisticated phishing campaign has emerged that expertly...

More like this

Hackers Exploit Industrial PLCs and Manipulate HMI Displays to Conceal Attacks

Title: Increasing Threat from Iranian Cyber Actors: Updated Advisory Highlights Risks to U.S. Critical...

South Korea Diplomatic Academy Experiences Data Breach

Significant Data Breach at South Korea's Diplomatic Academy: Personal Information Compromised In a troubling revelation,...

SBOM/CVE: The Shield in Cyber Warfare

We Are Conducting Security Drills for the Wrong Catastrophe: Understanding Cyber Threats Beyond "Duck...