type: incident ยท created: 2026-07-27 ยท updated: 2026-07-27 ยท tags: [ransomware, cybercrime-group, raas, ransomware-as-a-service, payload-builder, sector-technology] ยท confidence: medium ยท affected_sectors: [technology] ยท au_impact: true
DevMan RaaS Portal Centralises Payload Builds, Victim Management, and Affiliate Payouts
Continued coverage of the PRODAFT analysis of the Funky Mantis / DevMan RaaS operation, which operates a centrally administered web platform offering affiliates build generation, finance, victim chat, support, and payout functions โ representing an industrialisation of ransomware service delivery.
Key Details
- Source: The Hacker News (citing PRODAFT research)
- Date: 2026-07-25
- Reliability: Tier 2 โ Established cyber journalism
- Operation: Funky Mantis / DevMan RaaS
- Platform: Centrally administered web portal
- Capabilities:
- Payload/build generation
- Finance management
- Victim chat/negotiation interface
- Affiliate support
- Automated payout processing
- Significance: Represents industrialisation of ransomware-as-a-service delivery
Analysis
DevMan's centralised web platform model lowers the technical barrier to entry for ransomware affiliates, enabling less sophisticated actors to conduct ransomware operations. This operational model โ sometimes called 'RaaS 2.0' โ represents a significant evolution in the cybercrime ecosystem, moving from ad-hoc affiliate arrangements to a structured, platform-based service.
Cross-References
- Acsc Cisa Joint Advisory Russian State Sponsored Zimbra Phishing Campaign โ Russian cyber threat landscape, broader context
Source
- The Hacker News โ https://thehackernews.com/
- PRODAFT research (underlying analysis)
- Raw digest: Cyber Digest 2026 07 27