Cybersecurity researchers have uncovered new details about DevMan, a ransomware-as-a-service (RaaS) operation that has developed a sophisticated online management platform, allowing affiliates to create ransomware payloads, track victims, manage negotiations, and monitor earnings from a centralized dashboard.
A comprehensive report from Swiss cybersecurity firm PRODAFT reveals that the operation—tracked under the name Funky Mantis—has evolved into a highly organized cybercrime service that streamlines nearly every stage of a ransomware attack.
Centralized Dashboard Simplifies Ransomware Operations
According to PRODAFT, the DevMan portal functions as a complete management system for ransomware affiliates.
The web-based platform enables users to:
- Generate customized ransomware payloads
- Track infected victims
- Manage ransom negotiations
- Monitor affiliate payouts
- Access technical support
- Coordinate team activities
- Review operational statistics
Researchers say the platform also integrates network access services, allowing affiliates to either use their own compromised systems or obtain access provided through the ransomware program. Operators reportedly impose strict deadlines, requiring affiliates to complete attacks within two to three days.
Evolution From Affiliate to Independent RaaS
Security researchers believe DevMan first appeared in April 2025 as an affiliate working with established ransomware groups such as Qilin, DragonForce, Apos, and RansomHub before launching its own independent ransomware service.
Previous technical analyses suggested that DevMan’s malware shares significant similarities with DragonForce ransomware, indicating a common code lineage.
Advanced Portal Introduced in 2026
PRODAFT reports that the third version of the DevMan portal, introduced in January 2026, significantly expanded its capabilities.
New features include:
- Structured victim management
- Attack lifecycle tracking
- Team creation and invitation controls
- Per-victim payload customization
- Deadline monitoring
- Revenue tracking
- Shared operational access for affiliates
Researchers believe these enhancements demonstrate an effort to professionalize ransomware operations by replacing informal communication channels with a structured management system.
Defined Roles Within the Organization
The investigation identified several operational roles within the DevMan ecosystem, including administrators, access coordinators, senior operators, and affiliates responsible for deploying ransomware.
New affiliates reportedly receive guidance from experienced mentors after successfully compromising their first victim. Program administrators also retain authority to intervene in victim negotiations, remove inactive members, and enforce operational policies.
Revenue Sharing Model
The ransomware program follows an 80/20 profit-sharing model, allowing affiliates to retain the majority of ransom payments while the core operators receive the remaining share.
According to researchers, ransom proceeds are distributed to separate cryptocurrency wallets designated for affiliates and the central RaaS administrators.
Targeting Rules and Restrictions
DevMan’s internal policies permit attacks against organizations located outside the Commonwealth of Independent States (CIS) and Serbia while prohibiting attacks on CIS government-related entities and companies.
The group reportedly removed previous restrictions involving Saudi Arabia and explicitly encourages attacks on critical infrastructure. Affiliates seeking to target industrial environments are instructed to request a specialized encryptor designed for SCADA systems.
However, the operation claims to prohibit attacks against child-focused healthcare organizations and forbids intentionally leaking personal information belonging to minors.
Windows Locker Capabilities
PRODAFT’s technical analysis of the Windows ransomware payload identified numerous built-in capabilities commonly associated with advanced ransomware.