Alleged Huntress Insider Leaked Law Enforcement Communications to DevMan Ransomware Operation (DragonForce/Conti Lineage)

Alleged Huntress Insider Leaked Law Enforcement (TL-2026-0970), also tracked as Operation DevMan, is a high-severity supply-chain compromise, first published 2026-06-28. It is attributed to DevMan with medium confidence, affects Huntress Labs Huntress MDR Platform, maps to 34 MITRE ATT&CK techniques (T1003, T1005, T1014), and is covered by 9 detection rules and 22 indicators of compromise.

Key facts for TL-2026-0970

Threat ID
TL-2026-0970
Also known as
Operation DevMan, DevMan's Place
Severity
HIGH
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
2026-06-28
Last reviewed
2026-06-28
Attribution
DevMan
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
managed-security-services, health, finance, government administration, manufacturing, transport, technology, legal, insurance
Target regions
North America, Asia-Pacific, Europe, Africa, Middle East
Detection rules
9
Indicators of compromise
22

Malware and tooling in Alleged Huntress Insider Leaked Law Enforcement

Malware and tooling: DEVMAN, DragonForce, DevMan RaaS Web Dashboard

Former Huntress security analyst Ben Folland publicly alleged in June 2026 that a current Huntress employee passed US law enforcement (FBI) communications to DevMan, a ransomware group that emerged April 2025 as a DragonForce affiliate before launching an independent RaaS platform in September 2025. Huntress CEO Kyle Hanslovan acknowledged 'poor judgment in communicating with a cybercriminal' but disputed the 'insider' framing, citing active law enforcement coordination. If substantiated, the incident represents a critical supply-chain compromise of a managed detection and response (MDR) vendor with broad customer visibility into victim environments.

How Alleged Huntress Insider Leaked Law Enforcement works

This threat record documents two interlinked intelligence threads: (1) an alleged insider threat at Huntress, a widely-deployed managed detection and response (MDR) vendor, and (2) the emergence and operations of DevMan, a ransomware group with direct lineage from DragonForce and ultimately Conti v3.

**Insider Threat at Huntress (Alleged)** Ben Folland, a former Huntress security operations analyst, publicly alleged on social media in late June 2026 that a current Huntress employee passed US law enforcement communications — including FBI material — to operators of the DevMan ransomware group. Folland states he discovered the incident in December 2025 and resigned on February 19, 2026, citing irreconcilable conflict of interest. He claims the FBI identified the insider but that the individual remains employed at Huntress.

Folland promised to publish supporting evidence: direct communications between the Huntress employee and DevMan operators, FBI correspondence, recorded phone calls, internal Huntress memos, and evidence of threats made against Folland and his family. He also alleged Huntress was concealing the incident from partners, customers, and employees to protect an anticipated IPO.

Huntress CEO Kyle Hanslovan responded on Reddit, acknowledging that 'a former employee raised concerns that a teammate exercised poor judgment in communicating with a cybercriminal,' but strongly disputed the 'insider threat' characterization and the IPO prioritization accusation. Hanslovan noted that security researchers sometimes communicate with cybercriminals as part of legitimate intelligence-gathering — implying the contact may have been framed as research. He stated that active law enforcement coordination and legal proceedings prevent full public disclosure.

The supply-chain risk dimension is significant: Huntress has deep endpoint visibility across thousands of SMB and enterprise customer environments through its MDR platform. Any compromise of Huntress personnel — whether the insider leaked operational data, customer environment details, or law enforcement investigation timelines — could enable threat actors to evade arrest, time attacks optimally, or target Huntress-defended organizations with foreknowledge of detection capabilities.

**DevMan Ransomware: Emergence and Operations** DevMan first appeared in mid-April 2025 as an affiliate of both Qilin (Agenda) and DragonForce, operating under the DragonForce 'Dragons-as-a-Service' cartel model. Early analysis by ANY.RUN and Broadcom confirmed that DevMan payloads were built using the DragonForce builder, inheriting code derived from the leaked Conti v3 source code (the February 2022 Conti leak that seeded numerous ransomware families).

The lineage chain is: **Conti v3 (leaked Feb 2022) → DragonForce (adapted Conti codebase, added BYOVD, ChaCha8) → DevMan (DragonForce affiliate, modified variant)**.

DevMan v1.0 technical profile: - File extension: `.DEVMAN` (v1.0), `.devmanv1`, `.devman1` (v2.0) - Ransom notes: `README.devmanv1.txt`, `README.txt`, `README.yAGRTb.txt` - Critical builder flaw: self-encrypts its own ransom notes (encrypted notes renamed deterministically to `e47qfsnz2trbkhnt.devman`), undermining victim negotiation - Encryption: AES-256 (CBC) + RSA-2048 hybrid - Mutex: `hsfjuukjzloqu28oajh727190` - C2: Primarily offline; SMB probing for lateral movement; no persistent external C2 beacon - Registry persistence: `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`; `HKCU\Software\Microsoft\RestartManager\Session0000` - Platform inconsistency: wallpaper change works on Windows 10, fails on Windows 11 — indicative of incomplete QA

DevMan claimed 9 victims in April 2025 alone; by Q2 2025 had approximately 40-50 confirmed victims; by early 2026 over 120 confirmed victims spanning Asia-Pacific (majority), Africa, Europe, and North America.

In July 2025, researcher GangExposed doxed DevMan operators, triggering affiliate abandonment and operational disruption. DevMan recovered, simultaneously splitting from DragonForce and launching 'DevMan's Place,' an independent TOR-hosted leak site. In September 2025, DevMan launched DevMan 2.0 — a full RaaS platform with Rust-written encryptors for Windows, Linux/NAS, and ESXi; a web-based affiliate dashboard; GPO-based domain-wide deployment; and strict affiliate vetting requirements ($10,000 deposit, prior RaaS experience, 100+ GB exfiltrated proof-of-compromise). Revenue sharing tiers scale from 22% (targets under $20M revenue) down to negotiated rates for large enterprises.

**Attribution and Geopolitics** DevMan enforces a CIS exclusion zone (will not attack CIS-region organizations) and a Serbia exclusion, as well as a prohibition on attacks against child-related healthcare entities. These geographic restrictions are consistent with Eastern European threat actor norms but do not confirm nation-state affiliation. No formal government attribution has been established.

The Huntress insider's identity and national affiliation remain unknown and alleged only; no criminal charges were public at the time of this research.

MITRE ATT&CK techniques used in TL-2026-0970

Credential Access

T1003 OS Credential Dumping

Collection

T1005 Data from Local System; T1074 Data Staged; T1213 Data from Information Repositories

Defense Evasion

T1014 Rootkit; T1036 Masquerading; T1070 Indicator Removal

Discovery

T1018 Remote System Discovery; T1069 Permission Groups Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1135 Network Share Discovery

Lateral Movement

T1021 Remote Services

Exfiltration

T1048 Exfiltration Over Alternative Protocol; T1567 Exfiltration Over Web Service

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1547 Boot or Logon Autostart Execution

Command and Control

T1071 Application Layer Protocol; T1102 Web Service; T1573 Encrypted Channel

Initial Access

T1078 Valid Accounts; T1195 Supply Chain Compromise; T1199 Trusted Relationship

Persistence

T1078 Valid Accounts; T1547 Boot or Logon Autostart Execution

defense-impairment

T1112 Modify Registry; T1685 Disable or Modify Tools

Impact

T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1491 Defacement

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities

Affected products and versions in Alleged Huntress Insider Leaked Law Enforcement

  • Huntress Labs — Huntress MDR Platform
    Vulnerable versions: all versions (personnel-level compromise alleged)
    Fixed in: under investigation
  • Multiple — Windows Server / Windows 10 / Windows 11
    Vulnerable versions: Windows 10; Windows Server 2016; Windows Server 2019; Windows Server 2022
  • Multiple — Linux / NAS / VMware ESXi
    Vulnerable versions: DevMan 2.0+ targets Linux, NAS devices, and ESXi hypervisors

Remediation for Alleged Huntress Insider Leaked Law Enforcement

Immediate actions

  • Block all DevMan TOR infrastructure and known IOCs at perimeter (onion addresses in threat_iocs)
  • Block DevMan operator contact channels (devmanransomware@proton.me, TOX ID) in DLP/email gateway
  • Audit MDR vendor personnel with access to law enforcement communications or investigation timelines
  • Suspend sharing of active law enforcement operational details with external security vendors pending insider threat review
  • Block DevMan file extensions (.DEVMAN, .devmanv1, .devman1) at endpoint if feasible without operational impact
  • Block known DevMan SHA256 hashes in EDR/AV
  • Review Windows Registry Run key entries and Restart Manager session entries for DevMan persistence artifacts

Workarounds

  • Disable SMB admin shares on endpoints where lateral movement is not operationally required
  • Enable VSS (Volume Shadow Copy Service) protection policies — DevMan deletes shadow copies for recovery inhibition
  • Restrict Registry Run key write access via AppLocker/WDAC policies

Longer-term hardening

  • Implement zero-trust access controls for all MDR vendor personnel, limiting access to only required customer environment data
  • Establish strict need-to-know compartmentalization for law enforcement coordination communications
  • Deploy immutable offline backups with tested restoration procedures to resist ransomware impact
  • Implement GPO-restriction policies to prevent unauthorized domain-wide policy changes (DevMan 2.0 uses GPO for mass deployment)
  • Monitor for SMB lateral movement patterns consistent with DevMan (Restart Manager API calls, admin share enumeration)
  • Deploy behavioral detection rules for Conti/DragonForce/DevMan ransomware lineage patterns (see detections)
  • Conduct BYOVD (Bring Your Own Vulnerable Driver) defense: driver allowlist enforcement to block kernel-level security tool termination
  • Evaluate MDR vendor security posture, background check programs, and insider threat detection capabilities before renewing or expanding contracts

Weaknesses (CWE) in Alleged Huntress Insider Leaked Law Enforcement

CWE-506, CWE-312, CWE-284, CWE-522

Timeline of Alleged Huntress Insider Leaked Law Enforcement

  • Conti v3 ransomware source code leaked publicly, seeding a generation of derivative ransomware families including DragonForce and ultimately DevMan.
  • DragonForce ransomware began claiming victims on its leak site, initially using a LockBit 3.0 builder before transitioning to a modified Conti v3 codebase.
  • DragonForce released an updated strain based on Conti v3 source code, adding BYOVD (Bring Your Own Vulnerable Driver) capability for kernel-level security tool termination and ChaCha8 encryption for improved performance.
  • DragonForce rebranded as a 'cartel' offering a Dragons-as-a-Service affiliate model, allowing affiliates to white-label payloads, create branded variants, and operate under DragonForce infrastructure with full TOR hosting and leak site access.
  • DevMan emerged as a new ransomware threat actor, initially operating as an affiliate of both Qilin (Agenda) and DragonForce. First victim — French transport company 'doumen' — claimed via X (Twitter). DevMan payloads confirmed as built using DragonForce builder, inheriting Conti v3 code.
  • DevMan expanded to 12-13 victims in May 2025, rising to among the top-tier ransomware groups that month. Notable attacks included a National Social Security Fund (2.5 TB exfiltrated, $2.5M ransom) and a Thai media outlet (170 GB stolen).
  • Security researcher GangExposed publicly doxed alleged DevMan operator identities, causing temporary affiliate abandonment. DevMan operations continued despite the disruption.
  • ANY.RUN published forensic analysis of DevMan payloads, confirming DragonForce/Conti lineage, documenting the critical builder flaw causing self-encryption of ransom notes, and detailing the AES-256/RSA-2048 hybrid encryption scheme and mutex string hsfjuukjzloqu28oajh727190.
  • DevMan split from DragonForce, launching 'DevMan's Place' as an independent TOR-hosted leak site. DevMan operators publicly stated 'we stopped using DragonForce months ago.'
  • DevMan launched DevMan 2.0 — a full RaaS platform featuring Rust-written encryptors for Windows, Linux/NAS, and ESXi; a web-based affiliate dashboard; GPO-based domain-wide deployment capability; strict affiliate vetting ($10,000 deposit, prior RaaS experience, 100+ GB proof-of-compromise); and tiered revenue sharing (7-22% depending on target revenue). By this point DevMan had approximately 70-86 confirmed victims.
  • Ben Folland, then a Huntress security operations analyst, alleged he discovered evidence that a current Huntress employee was passing US law enforcement (FBI) communications to DevMan ransomware operators.
  • DevMan targeted healthcare sector with attacks on Abdulhadi Hospital (246 GB exfiltrated, $350K ransom) and Easter Seals (236 GB exfiltrated, $90K ransom), demonstrating willingness to attack healthcare despite stated prohibition on 'child-related healthcare' targets.
  • DevMan confirmed additional victims in February 2026: Crystal Coast Pain Management (North Carolina), Encompass Inc. (Minnesota), and Westervelt Johnson Nicoll & Keller LLC (Illinois), bringing total confirmed victims past 120.
  • Ben Folland resigned from Huntress citing irreconcilable conflict of interest related to the alleged insider incident. Huntress later confirmed a former employee raised concerns about a teammate's communications with a cybercriminal.
  • Ben Folland publicly alleged the Huntress insider incident via social media. The Register covered the story. Folland promised to publish supporting evidence including FBI correspondence, direct Huntress-employee-to-DevMan messages, recorded phone calls, internal memos, and evidence of threats against himself and his family. Huntress CEO Kyle Hanslovan issued a Reddit response acknowledging 'poor judgment in communicating with a cybercriminal' while disputing the insider framing and citing active law enforcement coordination.

Sources cited for Alleged Huntress Insider Leaked Law Enforcement

Threats related to Alleged Huntress Insider Leaked Law Enforcement

Detection coverage for TL-2026-0970

As of 2026-06-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0970 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-0970

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats