Alleged Insider Threat at Huntress: Analyst Accuses Employee of Leaking US Law-Enforcement Communications to DevMan Ransomware Operator

Alleged Insider Threat at Huntress (TL-2026-0945), also tracked as Huntress insider threat allegation, is a high-severity tracked intrusion set, first published 2026-06-25. It is attributed to DevMan with low confidence, affects Huntress Huntress Managed Security Platform (EDR/MDR), maps to 18 MITRE ATT&CK techniques (T1005, T1021, T1027), and is covered by 9 detection rules and 16 indicators of compromise.

Key facts for TL-2026-0945

Threat ID
TL-2026-0945
Also known as
Huntress insider threat allegation, Folland-Hanslovan dispute
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-06-25
Last reviewed
2026-06-25
Attribution
DevMan
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, cybersecurity, managed-security-services, government, critical-infrastructure, healthcare, financial
Target regions
North America, Europe, Asia, Africa
Detection rules
9
Indicators of compromise
16

Malware and tooling in Alleged Insider Threat at Huntress

Malware and tooling: DEVMAN, WinLocker

Former Huntress SOC analyst Ben Folland publicly alleged that a current Huntress employee passed US law-enforcement communications to a cybercriminal tied to the DevMan ransomware operation (a modified-DragonForce, Conti-lineage RaaS that emerged April 2025). Huntress CEO Kyle Hanslovan acknowledged a teammate 'exercised poor judgment' communicating with a possible cybercriminal, framing such contact as intelligence-gathering, while FBI coordination and ongoing legal proceedings limit disclosure.

How Alleged Insider Threat at Huntress works

On 25 June 2026 The Register reported a public dispute in which Ben Folland, a former Huntress security operations analyst whose last day was 19 February 2026, alleged that a still-employed Huntress staffer had passed sensitive US law-enforcement communications to a cybercriminal associated with the DevMan ransomware operation. Folland said he first discovered the alleged insider activity in December 2025, that the employee was 'caught by the FBI' yet remained employed, and that he himself was subsequently targeted (including threats referencing his family). Folland further alleged Huntress prioritized an upcoming IPO over client security and used legal threats to silence him. The dispute surfaced publicly in June 2026 as Folland responded to Huntress's disclosure of the Klue Salesforce supply-chain compromise (Huntress was among hundreds of Klue victims; the Klue data theft was claimed by the 'Icarus' extortion group).

Huntress CEO Kyle Hanslovan responded that a teammate 'exercised poor judgment in communicating with a' potential cybercriminal, asserting that security researchers occasionally maintain such contact to gather intelligence, and that ongoing legal proceedings and FBI coordination constrained what the company could say publicly.

This record is an insider-threat / supply-chain-trust intelligence item, not a vulnerability: the source article reports no CVE, malware hashes, or network IOCs specific to the alleged leak itself. The threat significance is the human-trust failure at a widely-deployed security vendor (an EDR/MDR provider with privileged telemetry across customer estates), where an insider with access to law-enforcement-sensitive communications allegedly fed them to a ransomware operator. The counterparty, DevMan, is a well-documented threat: it emerged in mid-April 2025 as an affiliate of Qilin/Agenda and DragonForce, split to operate independently using a modified version of the leaked DragonForce builder (itself derived from leaked Conti source) in July 2025, and launched the 'DevMan 2.0' Ransomware-as-a-Service platform on 30 September 2025. DevMan exhibits Conti-derived Windows Restart Manager abuse, SMB/ADMIN$ lateral movement, three encryption modes (full, header-only, custom), a .DEVMAN extension, a hardcoded mutex, builder flaws (self-encrypting ransom notes; wallpaper change failing on Windows 11), and Russian-language / CIS-Serbian affiliate ties. The DevMan-side malware and infrastructure IOCs in this record are documented from public ANY.RUN and Analyst1 reporting and are included to support hunting and attribution; the insider-leak allegation itself remains unproven and under legal/FBI process.

MITRE ATT&CK techniques used in TL-2026-0945

Collection

T1005 Data from Local System; T1213 Data from Information Repositories

Lateral Movement

T1021 Remote Services

Defense Evasion

T1027 Obfuscated Files or Information; T1070 Indicator Removal

Execution

T1053 Scheduled Task/Job; T1204 User Execution

Initial Access

T1078 Valid Accounts; T1199 Trusted Relationship

Discovery

T1135 Network Share Discovery

Impact

T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1491 Defacement; T1657 Financial Theft

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities

Affected products and versions in Alleged Insider Threat at Huntress

  • Huntress — Huntress Managed Security Platform (EDR/MDR)
    Vulnerable versions: organizational / personnel-trust scope
  • DragonForce — DragonForce / DevMan ransomware builder (leaked, Conti-derived)
    Vulnerable versions: DevMan modified DragonForce variant; DevMan 2.0 RaaS

Remediation for Alleged Insider Threat at Huntress

Immediate actions

  • Treat the allegation as unverified pending FBI/legal process; do not act on attribution claims as fact.
  • For organizations using Huntress or similar privileged-access security vendors, review what telemetry, communications, and law-enforcement-sensitive data third parties can access.
  • Block known DevMan .onion infrastructure and Tox/Session contact identifiers at egress and in DLP/insider-risk monitoring.
  • Hunt for DevMan host artifacts: .DEVMAN extension, mutex 'hsfjuukjzloqu28oajh727190', and Restart Manager registry abuse under Session0000.

Workarounds

  • Disable or scope down unused/legacy SaaS-integration credentials and OAuth tokens (lesson reinforced by the concurrent Klue/Salesforce breach affecting Huntress).
  • Segment networks and restrict SMB/ADMIN$ access to limit DevMan-style lateral movement should ransomware follow an insider compromise.

Longer-term hardening

  • Implement insider-threat program controls: least-privilege access to law-enforcement-sensitive and case-coordination communications, separation of duties, and access logging with anomaly alerting.
  • Establish and enforce a documented, supervised policy governing analyst contact with suspected criminals for intelligence purposes (approval, logging, legal review).
  • Apply UEBA/insider-risk analytics to detect anomalous exfiltration of sensitive communications by privileged staff.
  • Vet and continuously monitor security-vendor supply-chain trust (least-privilege OAuth/SaaS integrations, as the parallel Klue compromise illustrates).

Weaknesses (CWE) in Alleged Insider Threat at Huntress

CWE-284, CWE-200, CWE-538, CWE-732, CWE-1265

Timeline of Alleged Insider Threat at Huntress

  • DevMan ransomware operation emerges, initially operating as an affiliate of Qilin/Agenda and DragonForce using a modified version of the leaked (Conti-derived) DragonForce builder.
  • ANY.RUN publishes forensic analysis of the DevMan DragonForce variant; DevMan transitions to independent operations and stands up its own infrastructure.
  • DevMan provides a security researcher pre-launch access to its new Ransomware-as-a-Service platform, five days before public announcement.
  • DevMan 2.0 Ransomware-as-a-Service platform launches publicly, recruiting non-CIS affiliates with a $10,000 deposit and proof-of-compromise requirements.
  • Ben Folland later states he first discovered the alleged Huntress insider activity (passing law-enforcement communications to a DevMan-linked criminal) in December 2025.
  • Ben Folland's last day as a security operations analyst at Huntress.
  • Concurrent context: threat actor compromises Klue backend via a legacy active credential, pivoting to steal Salesforce OAuth tokens of Klue customers including Huntress.
  • Huntress discloses the Klue Salesforce supply-chain data theft affecting its sales/CRM data; the extortion is later claimed by the 'Icarus' group.
  • The Register reports Folland's public allegations and CEO Kyle Hanslovan's response that a teammate 'exercised poor judgment' contacting a possible cybercriminal for intelligence; FBI coordination and legal proceedings limit disclosure.

Sources cited for Alleged Insider Threat at Huntress

Threats related to Alleged Insider Threat at Huntress

Detection coverage for TL-2026-0945

As of 2026-06-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0945 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats