Alleged Huntress Insider Leaked Law Enforcement Communications to DevMan Ransomware Operation (DragonForce/Conti Lineage) — Threadlinqs Intelligence
As of 2026-06-28, Alleged Huntress Insider Leaked Law Enforcement Communications to DevMan Ransomware Operation (DragonForce/Conti Lineage) is a high-severity supply chain threat attributed to DevMan, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-0970 · Severity: HIGH · Status: ACTIVE · Category: SUPPLY_CHAIN
Attribution: DevMan · FINANCIAL
Former Huntress security analyst Ben Folland publicly alleged in June 2026 that a current Huntress employee passed US law enforcement (FBI) communications to DevMan, a ransomware group that emerged
This threat record documents two interlinked intelligence threads: (1) an alleged insider threat at Huntress, a widely-deployed managed detection and response (MDR) vendor, and (2) the emergence and operations of DevMan, a ransomware group with direct lineage from DragonForce and ultimately Conti v3.
**Insider Threat at Huntress (Alleged)**
Ben Folland, a former Huntress security operations analyst, publicly alleged on social media in late June 2026 that a current Huntress employee passed US law enforcement communications — including FBI material — to operators of the DevMan ransomware group. Folland states he discovered the incident in December 2025 and resigned on February 19, 2026, citing irreconcilable conflict of interest. He claims the FBI identified the insider but that the individual remains employed at Huntress.
Folland promised to publish supporting evidence: direct communications between the Huntress employee and DevMan operators, FBI correspondence, recorded phone calls, internal Huntress memos, and evidence of threats made against Folland and his family. He also alleged Huntress was concealing the incident from partners, customers, and employees to protect an anticipated IPO.
Huntress CEO Kyle Hanslovan responded on Reddit, acknowledging that 'a former employee raised concerns that a teammate exercised poor judgment in communicating with a cybercriminal,' but strongly disputed the 'insider threat' characterization and the IPO prioritization accusation. Hanslovan noted that security researchers sometimes communicate with cybercriminals as part of legitimate intelligence-gathering — implying the contact may have been framed as research. He stated that active law enforcement coordination and legal proceedings prevent full public disclosure.
The supply-chain risk dimension is significant: Huntress has deep endpoint visibility across thousands of SMB and enterprise customer environments through its MDR platform. Any compromise of Huntress personnel — whether the insider leaked operational data, customer environment details, or law enforcement investigation timelines — could enable threat actors to evade arrest, time attacks optimally, or target Huntress-defended organizations with foreknowledge of detection capabilities.
**DevMan Ransomware: Emergence and Operations**
DevMan first appeared in mid-April 2025 as an affiliate of both Qilin (Agenda) and DragonForce, operating under the DragonForce 'Dragons-as-a-Service' cartel model. Early analysis by ANY.RUN and Broadcom confirmed that DevMan payloads were built using the DragonForce builder, inheriting code derived from the leaked Conti v3 source code (the February 2022 Conti leak that seeded numerous ransomware families).
The lineage chain is: **Conti v3 (leaked Feb 2022) → DragonForce (adapted Conti codebase, added BYOVD, ChaCha8) → DevMan (DragonForce affiliate, modified variant)**.
DevMan v1.0 technical profile:
- File extension: `.DEVMAN` (v1.0), `.devmanv1`, `.devman1` (v2.0)
- Ransom notes: `README.devmanv1.txt`, `README.txt`, `README.yAGRTb.txt`
- Critical builder flaw: self-encrypts its own ransom notes (encrypted notes renamed deterministically to `e47qfsnz2trbkhnt.devman`), undermining victim negotiation
- Encryption: AES-256 (CBC) + RSA-2048 hybrid
- Mutex: `hsfjuukjzloqu28oajh727190`
- C2: Primarily offline; SMB probing for lateral movement; no persistent external C2 beacon
- Registry persistence: `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`; `HKCU\Software\Microsoft\RestartManager\Session0000`
- Platform inconsistency: wallpaper change works on Windows 10, fails on Windows 11 — indicative of incomplete QA
DevMan claimed 9 victims in April 2025 alone; by Q2 2025 had approximately 40-50 confirmed victims; by early 2026 over 120 confirmed victims spanning Asia-Pacific (majority), Africa, Europe, and North America.
In July 2025, researcher GangExposed doxed DevMan operators, triggering affiliate abandonment and operational disruption. DevMan re
Weaknesses (CWE)
CWE-506, CWE-312, CWE-284, CWE-522
Target sectors: managed-security-services, health, finance, government administration, manufacturing, transport, technology, legal, insurance
Target regions: North America, Asia-Pacific, Europe, Africa, Middle East
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
SUPPLY_CHAIN, HIGH, threat intelligence, cybersecurity, T1078, T1199, T1195, T1583, T1585, T1587, T1059, T1204, T1547, T1078