Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-27 ยท updated: 2026-07-27 ยท tags: [ransomware, cybercrime-group, raas, ransomware-as-a-service, payload-builder, sector-technology] ยท confidence: medium ยท affected_sectors: [technology] ยท au_impact: true

DevMan RaaS Portal Centralises Payload Builds, Victim Management, and Affiliate Payouts

Continued coverage of the PRODAFT analysis of the Funky Mantis / DevMan RaaS operation, which operates a centrally administered web platform offering affiliates build generation, finance, victim chat, support, and payout functions โ€” representing an industrialisation of ransomware service delivery.

Key Details

  • Source: The Hacker News (citing PRODAFT research)
  • Date: 2026-07-25
  • Reliability: Tier 2 โ€” Established cyber journalism
  • Operation: Funky Mantis / DevMan RaaS
  • Platform: Centrally administered web portal
  • Capabilities:
  • Payload/build generation
  • Finance management
  • Victim chat/negotiation interface
  • Affiliate support
  • Automated payout processing
  • Significance: Represents industrialisation of ransomware-as-a-service delivery

Analysis

DevMan's centralised web platform model lowers the technical barrier to entry for ransomware affiliates, enabling less sophisticated actors to conduct ransomware operations. This operational model โ€” sometimes called 'RaaS 2.0' โ€” represents a significant evolution in the cybercrime ecosystem, moving from ad-hoc affiliate arrangements to a structured, platform-based service.

Cross-References

Source