DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
The DevMan ransomware-as-a-service (RaaS) operation has significantly upgraded its affiliate portal, transitioning from a chat-based system to a centralized platform for managing victims, payouts, and team operations. PRODAFT cybersecurity researchers have identified five distinct roles within the DevMan structure, highlighting a move towards formalized affiliate workflows and increased operational control by the RaaS administrators. The latest version of the portal, released in January 2026, includes features like structured victim records, team creation, and per-victim build options, reflecting a desire to streamline operations and manage multiple intrusions. The incident is further complicated by allegations of an insider threat at Huntress, where a researcher allegedly leaked information about an FBI investigation to DevMan, raising concerns about potential vulnerabilities in threat intelligence gathering and analysis.
The DevMan ransomware-as-a-service (RaaS) operation has undergone a significant evolution, moving from a decentralized, chat-based affiliate network to a more structured and centralized platform. Swiss cybersecurity company PRODAFT has been tracking the operation, now known as Funky Mantis, and has identified five distinct roles within the DevMan structure: LARVA-367 (Administrator/owner and central coordinator), LARVA-546 (Access coordinator), LARVA-547 (Senior operator), LARVA-548 (Senior operator or coordinator), and LARVA-550 (Affiliate/operator). The affiliate portal, now in version 3 (v3), released in January 2026, incorporates features designed to enhance operational efficiency and control, including structured victim records, team creation, and per-victim build options. This shift indicates a deliberate effort to formalize affiliate workflows and manage multiple intrusions through a common platform.
PRODAFT researchers noted that affiliates are added to corporate chat after producing a first victim and are assigned an experienced curator, who can remove them after one month without a new victim. Team formation and disclosure of program affiliation require curator approval, limiting independent coordination and public association with the service. The core management retains the right to take over a conversation if an affiliate behaves inappropriately or fails to adhere to a commitment, further reinforcing operational control. The RaaS program distributes profits with an 80/20 split, sending ransom funds to two wallets – one for the affiliate and one linked to the RaaS program.
DevMan’s targeting policy allows affiliates to strike entities outside the CIS countries and Serbia, excluding CIS consulates and CIS-linked companies, and lifts a previous restriction on Saudi Arabia. Beyond encouraging attacks against critical infrastructure, the policy instructs affiliates to request a separate encryptor for SCADA systems, corroborating their development on a specialized SCADA locker. However, affiliates are forbidden from attacking child-related healthcare businesses and intentional leaks of personal data belonging to people under the age of 18.
The latest version of the portal allows affiliates to create lockers for Windows, ESXi, or Linux. An analysis of the Windows version has identified functions related to privilege checking (to determine if it’s running as an administrator), security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion. The locker encrypts files with ChaCha20-Poly1305, fully encrypting files up to and including 3 MiB, while those above the threshold are partially encrypted by processing a 1 MiB chunk every 51 MiB.
Adding to the complexity, a former Huntress analyst, Ben Folland, has alleged that a current Huntress employee deliberately leaked information about an FBI investigation into DevMan to the ransomware group. Folland claims the analyst disclosed the FBI’s efforts to track DevMan, including agent names and screenshots, in a deliberate attempt to aid the threat actor. Huntress CEO Kyle Hanslovan acknowledged the incident, stating that the company is investigating “questionable, long-term threat actor communications” between a current team member and a threat actor, describing it as “poor judgment.” He added that the company is continuing its investigation and has taken administrative actions. Folland disagrees, arguing that the analyst's actions constitute an “insider threat” and that they should be considered a deliberate attempt to assist DevMan. The FBI has reportedly contacted the Huntress employee to gather intelligence on DevMan, further highlighting the potential risks associated with sharing sensitive threat intelligence information.
