DevMan Ransomware Runs a One-Stop Web Portal for Its Criminal Affiliates

Swiss researchers say the operation, tracked as Funky Mantis, gives partners a single dashboard to build malware, chase payments, and manage victims.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • Swiss cybersecurity firm PRODAFT is tracking the DevMan ransomware operation under the name Funky Mantis.
  • The gang runs a single web portal where affiliates build malware, watch earnings, and manage victims.
  • Ransomware-as-a-service means the core group rents its tools to other criminals in exchange for a cut.
  • Centralised portals like this one lower the skill bar for would-be attackers.
  • Naming and tracking such platforms helps defenders map the wider criminal supply chain.

The people behind the DevMan ransomware scheme have built themselves an office in a browser tab.

Ransomware, for readers new to the term, is malicious software that scrambles a company's files and demands payment to unlock them. DevMan sells that capability to other criminals. Researchers call this model ransomware-as-a-service, or RaaS: the core group writes the code, and affiliates do the breaking-in, splitting the profits.

Swiss cybersecurity company PRODAFT, which studies criminal networks, is tracking the DevMan operation under the name Funky Mantis. Different vendors give the same gangs different names, so expect to see other labels appear over time. For now, treat the Funky Mantis tag as PRODAFT's, with medium confidence that it maps cleanly to the DevMan brand seen on leak sites.

What is the DevMan portal, in plain terms?

It is a website only affiliates can log into, and it packages every job a ransomware crook needs to do into one place. Think of it as the criminal version of a software-as-a-service dashboard.

According to PRODAFT, first reported by The Hacker News, the portal handles three jobs at once: generating fresh malware samples for each attack, tracking who has paid and who has not, and managing the list of victims the affiliate is squeezing. That combination is what makes it notable.

Most ransomware crews still stitch these tasks together with chat groups, spreadsheets, and separate builder tools. A single web app is tidier, faster, and easier for a newcomer to pick up.

Why does a slick portal matter?

It lowers the skill bar. A criminal who could not previously assemble their own toolkit can now click a few buttons and walk out with a ready-to-deploy payload.

That pattern is not new. Groups like LockBit and the now-defunct Conti pushed the same model years ago, and their affiliate panels are part of why ransomware became an industry rather than a hobby. Funky Mantis appears to be iterating on that template rather than inventing it.

Detail What PRODAFT reports
Operation name (PRODAFT) Funky Mantis
Public brand DevMan
Model Ransomware-as-a-service
Portal functions Payload builds, finance tracking, victim management

Should ordinary people be worried?

Not directly, but indirectly, yes. You will not log into the DevMan portal. Your dentist's office, your kid's school district, or your local council might end up on the other side of it.

If a service you use is hit by ransomware, watch for two things. First, a notice from the organisation telling you what data was exposed. Second, a spike in phishing attempts, where criminals send fake emails pretending to be that organisation to trick you into handing over passwords or card details. Treat unexpected messages with suspicion for a few months after any breach notice.

What can defenders take from this?

Capability is not the same as intent, and a shared toolkit does not mean shared operators. When incident responders see DevMan malware on a network, the person who deployed it could be any one of the affiliates renting the platform. That matters for attribution: overlapping infrastructure and overlapping TTPs, meaning the tactics, techniques and procedures attackers reuse, do not automatically point at one crew.

For now, PRODAFT's tracking gives defenders a name to hang indicators on. That alone is useful.

© 2026 Threat Vectr