Connect with us

Cybersecurity

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

Published

on

Cybersecurity researchers have uncovered new details about DevMan, a ransomware-as-a-service (RaaS) operation that has developed a sophisticated online management platform, allowing affiliates to create ransomware payloads, track victims, manage negotiations, and monitor earnings from a centralized dashboard.

A comprehensive report from Swiss cybersecurity firm PRODAFT reveals that the operation—tracked under the name Funky Mantis—has evolved into a highly organized cybercrime service that streamlines nearly every stage of a ransomware attack.

Centralized Dashboard Simplifies Ransomware Operations

According to PRODAFT, the DevMan portal functions as a complete management system for ransomware affiliates.

The web-based platform enables users to:

  • Generate customized ransomware payloads
  • Track infected victims
  • Manage ransom negotiations
  • Monitor affiliate payouts
  • Access technical support
  • Coordinate team activities
  • Review operational statistics

Researchers say the platform also integrates network access services, allowing affiliates to either use their own compromised systems or obtain access provided through the ransomware program. Operators reportedly impose strict deadlines, requiring affiliates to complete attacks within two to three days.

Evolution From Affiliate to Independent RaaS

Security researchers believe DevMan first appeared in April 2025 as an affiliate working with established ransomware groups such as Qilin, DragonForce, Apos, and RansomHub before launching its own independent ransomware service.

Previous technical analyses suggested that DevMan’s malware shares significant similarities with DragonForce ransomware, indicating a common code lineage.

Advanced Portal Introduced in 2026

PRODAFT reports that the third version of the DevMan portal, introduced in January 2026, significantly expanded its capabilities.

New features include:

  • Structured victim management
  • Attack lifecycle tracking
  • Team creation and invitation controls
  • Per-victim payload customization
  • Deadline monitoring
  • Revenue tracking
  • Shared operational access for affiliates

Researchers believe these enhancements demonstrate an effort to professionalize ransomware operations by replacing informal communication channels with a structured management system.

Defined Roles Within the Organization

The investigation identified several operational roles within the DevMan ecosystem, including administrators, access coordinators, senior operators, and affiliates responsible for deploying ransomware.

New affiliates reportedly receive guidance from experienced mentors after successfully compromising their first victim. Program administrators also retain authority to intervene in victim negotiations, remove inactive members, and enforce operational policies.

Revenue Sharing Model

The ransomware program follows an 80/20 profit-sharing model, allowing affiliates to retain the majority of ransom payments while the core operators receive the remaining share.

According to researchers, ransom proceeds are distributed to separate cryptocurrency wallets designated for affiliates and the central RaaS administrators.

Targeting Rules and Restrictions

DevMan’s internal policies permit attacks against organizations located outside the Commonwealth of Independent States (CIS) and Serbia while prohibiting attacks on CIS government-related entities and companies.

The group reportedly removed previous restrictions involving Saudi Arabia and explicitly encourages attacks on critical infrastructure. Affiliates seeking to target industrial environments are instructed to request a specialized encryptor designed for SCADA systems.

However, the operation claims to prohibit attacks against child-focused healthcare organizations and forbids intentionally leaking personal information belonging to minors.

Windows Locker Capabilities

PRODAFT’s technical analysis of the Windows ransomware payload identified numerous built-in capabilities commonly associated with advanced ransomware.

Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Copyright © 2023 Cyber Reports Cyber Security News All Rights Reserved Website by Top Search SEO