# DevMan

> As of 2026-07-25, DevMan is a threat actor tracked by Threadlinqs Intelligence across 4 threats spanning ransomware, supply chain, threat intel. ATT&CK coverage spans 57 techniques across 14 tactics in 4 of 4 tracked threats. Most-observed techniques: T1078 (Valid Accounts), T1486 (Data Encrypted for Impact), T1021 (Remote Services).

- **Tracked threats:** 4
- **Categories:** RANSOMWARE, SUPPLY_CHAIN, THREAT_INTEL
- **As of:** 2026-07-25

## ATT&CK techniques observed

57 techniques observed across 4 of 4 tracked threats. Tactics: Discovery (7), Execution (7), Impact (7), Initial Access (5), Resource Development (5), Lateral Movement (4).

- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 4 of 4 tracked threats
- [T1486](https://intel.threadlinqs.com/technique/T1486) Data Encrypted for Impact — Impact — observed in 4 of 4 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 3 of 4 tracked threats
- [T1070](https://intel.threadlinqs.com/technique/T1070) Indicator Removal — Stealth (formerly Defense Evasion) — observed in 3 of 4 tracked threats
- [T1135](https://intel.threadlinqs.com/technique/T1135) Network Share Discovery — Discovery — observed in 3 of 4 tracked threats
- [T1490](https://intel.threadlinqs.com/technique/T1490) Inhibit System Recovery — Impact — observed in 3 of 4 tracked threats
- [T1567](https://intel.threadlinqs.com/technique/T1567) Exfiltration Over Web Service — Exfiltration — observed in 3 of 4 tracked threats
- [T1583](https://intel.threadlinqs.com/technique/T1583) Acquire Infrastructure — Resource Development — observed in 3 of 4 tracked threats
- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 2 of 4 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 2 of 4 tracked threats
- [T1018](https://intel.threadlinqs.com/technique/T1018) Remote System Discovery — Discovery — observed in 2 of 4 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 4 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 2 of 4 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 2 of 4 tracked threats
- [T1112](https://intel.threadlinqs.com/technique/T1112) Modify Registry — Defense Impairment — observed in 2 of 4 tracked threats

## Tracked threats

- [DevMan RaaS ("Funky Mantis") Centralizes Payload Builds, Victim Management, and Affiliate Payouts, Develops SCADA-Destructive Locker](https://intel.threadlinqs.com/threat/TL-2026-1680) — CRITICAL
- [Alleged Huntress Insider Leaked Law Enforcement Communications to DevMan Ransomware Operation (DragonForce/Conti Lineage)](https://intel.threadlinqs.com/threat/TL-2026-0970) — HIGH
- [Alleged Insider Threat at Huntress: Analyst Accuses Employee of Leaking US Law-Enforcement Communications to DevMan Ransomware Operator](https://intel.threadlinqs.com/threat/TL-2026-0945) — HIGH
- [VECT 2.0 / DEVMAN 3.0 Ransomware — Design-Flawed ChaCha20 Encryption Irreversibly Destroys Files Over 128KB on Windows, Linux & ESXi (Wiper by Accident)](https://intel.threadlinqs.com/threat/TL-2026-0697) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/DevMan
