DevMan RaaS Portal Streamlines Payload Builds, Victim Tracking, and Affiliate Payouts
What happened
Swiss cybersecurity firm PRODAFT has identified a dedicated web portal operated by the group behind the DevMan ransomware-as-a-service (RaaS) scheme, which it tracks under the name Funky Mantis. According to PRODAFT, the portal centralizes several affiliate-facing functions in one place: building ransomware payloads, managing finances/payouts, and overseeing aspects of victim management.
Why it matters for defenders
RaaS platforms that consolidate build generation, victim tracking, and affiliate finance into a single administered portal lower the technical bar for affiliates and make it easier to onboard and manage larger affiliate networks. This kind of operational tooling typically correlates with an increase in the scale and consistency of intrusions carried out by affiliates using the platform, since payloads and processes are standardized rather than ad hoc. Organizations across sectors targeted by RaaS affiliates should treat this as a signal that DevMan/Funky Mantis-linked activity may become more frequent or more organized.
What defenders should watch for or do now
- Maintain strong detection coverage for common ransomware affiliate tradecraft: initial access via phishing, exposed remote services, or valid account abuse; lateral movement via RDP/SMB; credential dumping; and use of legitimate remote management tools.
- Monitor for rapid mass file modification/encryption behavior, shadow copy deletion, and backup tampering, which are common precursors to and hallmarks of ransomware deployment regardless of the specific RaaS brand.
- Ensure endpoint detection and response (EDR) coverage, offline/immutable backups, and tested incident response and restoration procedures are in place, since standardized affiliate tooling can mean faster time-to-impact once access is gained.
- Track threat intelligence updates from PRODAFT and other researchers for any indicators of compromise, TTPs, or infrastructure specifically tied to DevMan/Funky Mantis as they emerge.
Developing intel
This is based on early reporting and PRODAFT's tracking of the operation; further technical details (such as specific IOCs, TTPs, or victim sectors) had not been fully disclosed at the time of writing. For the original report, see The Hacker News.