Alleged Huntress Insider Leaked Law Enforcement Communications to DevMan Ransomware Operation (DragonForce/Conti Lineage)
Alleged Huntress Insider Leaked Law Enforcement (TL-2026-0970), also tracked as Operation DevMan, is a high-severity supply-chain compromise, first published 2026-06-28. It is attributed to DevMan with medium confidence, affects Huntress Labs Huntress MDR Platform, maps to 34 MITRE ATT&CK techniques (T1003, T1005, T1014), and is covered by 9 detection rules and 22 indicators of compromise.
Key facts for TL-2026-0970
- Threat ID
- TL-2026-0970
- Also known as
- Operation DevMan, DevMan's Place
- Severity
- HIGH
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- 2026-06-28
- Last reviewed
- 2026-06-28
- Attribution
- DevMan
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- managed-security-services, health, finance, government administration, manufacturing, transport, technology, legal, insurance
- Target regions
- North America, Asia-Pacific, Europe, Africa, Middle East
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in Alleged Huntress Insider Leaked Law Enforcement
Malware and tooling: DEVMAN, DragonForce, DevMan RaaS Web Dashboard
Former Huntress security analyst Ben Folland publicly alleged in June 2026 that a current Huntress employee passed US law enforcement (FBI) communications to DevMan, a ransomware group that emerged April 2025 as a DragonForce affiliate before launching an independent RaaS platform in September 2025. Huntress CEO Kyle Hanslovan acknowledged 'poor judgment in communicating with a cybercriminal' but disputed the 'insider' framing, citing active law enforcement coordination. If substantiated, the incident represents a critical supply-chain compromise of a managed detection and response (MDR) vendor with broad customer visibility into victim environments.
How Alleged Huntress Insider Leaked Law Enforcement works
This threat record documents two interlinked intelligence threads: (1) an alleged insider threat at Huntress, a widely-deployed managed detection and response (MDR) vendor, and (2) the emergence and operations of DevMan, a ransomware group with direct lineage from DragonForce and ultimately Conti v3.
**Insider Threat at Huntress (Alleged)** Ben Folland, a former Huntress security operations analyst, publicly alleged on social media in late June 2026 that a current Huntress employee passed US law enforcement communications — including FBI material — to operators of the DevMan ransomware group. Folland states he discovered the incident in December 2025 and resigned on February 19, 2026, citing irreconcilable conflict of interest. He claims the FBI identified the insider but that the individual remains employed at Huntress.
Folland promised to publish supporting evidence: direct communications between the Huntress employee and DevMan operators, FBI correspondence, recorded phone calls, internal Huntress memos, and evidence of threats made against Folland and his family. He also alleged Huntress was concealing the incident from partners, customers, and employees to protect an anticipated IPO.
Huntress CEO Kyle Hanslovan responded on Reddit, acknowledging that 'a former employee raised concerns that a teammate exercised poor judgment in communicating with a cybercriminal,' but strongly disputed the 'insider threat' characterization and the IPO prioritization accusation. Hanslovan noted that security researchers sometimes communicate with cybercriminals as part of legitimate intelligence-gathering — implying the contact may have been framed as research. He stated that active law enforcement coordination and legal proceedings prevent full public disclosure.
The supply-chain risk dimension is significant: Huntress has deep endpoint visibility across thousands of SMB and enterprise customer environments through its MDR platform. Any compromise of Huntress personnel — whether the insider leaked operational data, customer environment details, or law enforcement investigation timelines — could enable threat actors to evade arrest, time attacks optimally, or target Huntress-defended organizations with foreknowledge of detection capabilities.
**DevMan Ransomware: Emergence and Operations** DevMan first appeared in mid-April 2025 as an affiliate of both Qilin (Agenda) and DragonForce, operating under the DragonForce 'Dragons-as-a-Service' cartel model. Early analysis by ANY.RUN and Broadcom confirmed that DevMan payloads were built using the DragonForce builder, inheriting code derived from the leaked Conti v3 source code (the February 2022 Conti leak that seeded numerous ransomware families).
The lineage chain is: **Conti v3 (leaked Feb 2022) → DragonForce (adapted Conti codebase, added BYOVD, ChaCha8) → DevMan (DragonForce affiliate, modified variant)**.
DevMan v1.0 technical profile: - File extension: `.DEVMAN` (v1.0), `.devmanv1`, `.devman1` (v2.0) - Ransom notes: `README.devmanv1.txt`, `README.txt`, `README.yAGRTb.txt` - Critical builder flaw: self-encrypts its own ransom notes (encrypted notes renamed deterministically to `e47qfsnz2trbkhnt.devman`), undermining victim negotiation - Encryption: AES-256 (CBC) + RSA-2048 hybrid - Mutex: `hsfjuukjzloqu28oajh727190` - C2: Primarily offline; SMB probing for lateral movement; no persistent external C2 beacon - Registry persistence: `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`; `HKCU\Software\Microsoft\RestartManager\Session0000` - Platform inconsistency: wallpaper change works on Windows 10, fails on Windows 11 — indicative of incomplete QA
DevMan claimed 9 victims in April 2025 alone; by Q2 2025 had approximately 40-50 confirmed victims; by early 2026 over 120 confirmed victims spanning Asia-Pacific (majority), Africa, Europe, and North America.
In July 2025, researcher GangExposed doxed DevMan operators, triggering affiliate abandonment and operational disruption. DevMan recovered, simultaneously splitting from DragonForce and launching 'DevMan's Place,' an independent TOR-hosted leak site. In September 2025, DevMan launched DevMan 2.0 — a full RaaS platform with Rust-written encryptors for Windows, Linux/NAS, and ESXi; a web-based affiliate dashboard; GPO-based domain-wide deployment; and strict affiliate vetting requirements ($10,000 deposit, prior RaaS experience, 100+ GB exfiltrated proof-of-compromise). Revenue sharing tiers scale from 22% (targets under $20M revenue) down to negotiated rates for large enterprises.
**Attribution and Geopolitics** DevMan enforces a CIS exclusion zone (will not attack CIS-region organizations) and a Serbia exclusion, as well as a prohibition on attacks against child-related healthcare entities. These geographic restrictions are consistent with Eastern European threat actor norms but do not confirm nation-state affiliation. No formal government attribution has been established.
The Huntress insider's identity and national affiliation remain unknown and alleged only; no criminal charges were public at the time of this research.
MITRE ATT&CK techniques used in TL-2026-0970
Credential Access
Collection
T1005 Data from Local System; T1074 Data Staged; T1213 Data from Information Repositories
Defense Evasion
T1014 Rootkit; T1036 Masquerading; T1070 Indicator Removal
Discovery
T1018 Remote System Discovery; T1069 Permission Groups Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1135 Network Share Discovery
Lateral Movement
Exfiltration
T1048 Exfiltration Over Alternative Protocol; T1567 Exfiltration Over Web Service
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1547 Boot or Logon Autostart Execution
Command and Control
T1071 Application Layer Protocol; T1102 Web Service; T1573 Encrypted Channel
Initial Access
T1078 Valid Accounts; T1195 Supply Chain Compromise; T1199 Trusted Relationship
Persistence
T1078 Valid Accounts; T1547 Boot or Logon Autostart Execution
defense-impairment
T1112 Modify Registry; T1685 Disable or Modify Tools
Impact
T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1491 Defacement
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities
Affected products and versions in Alleged Huntress Insider Leaked Law Enforcement
- Huntress Labs — Huntress MDR Platform
Vulnerable versions: all versions (personnel-level compromise alleged)
Fixed in: under investigation - Multiple — Windows Server / Windows 10 / Windows 11
Vulnerable versions: Windows 10; Windows Server 2016; Windows Server 2019; Windows Server 2022 - Multiple — Linux / NAS / VMware ESXi
Vulnerable versions: DevMan 2.0+ targets Linux, NAS devices, and ESXi hypervisors
Remediation for Alleged Huntress Insider Leaked Law Enforcement
Immediate actions
- Block all DevMan TOR infrastructure and known IOCs at perimeter (onion addresses in threat_iocs)
- Block DevMan operator contact channels (devmanransomware@proton.me, TOX ID) in DLP/email gateway
- Audit MDR vendor personnel with access to law enforcement communications or investigation timelines
- Suspend sharing of active law enforcement operational details with external security vendors pending insider threat review
- Block DevMan file extensions (.DEVMAN, .devmanv1, .devman1) at endpoint if feasible without operational impact
- Block known DevMan SHA256 hashes in EDR/AV
- Review Windows Registry Run key entries and Restart Manager session entries for DevMan persistence artifacts
Workarounds
- Disable SMB admin shares on endpoints where lateral movement is not operationally required
- Enable VSS (Volume Shadow Copy Service) protection policies — DevMan deletes shadow copies for recovery inhibition
- Restrict Registry Run key write access via AppLocker/WDAC policies
Longer-term hardening
- Implement zero-trust access controls for all MDR vendor personnel, limiting access to only required customer environment data
- Establish strict need-to-know compartmentalization for law enforcement coordination communications
- Deploy immutable offline backups with tested restoration procedures to resist ransomware impact
- Implement GPO-restriction policies to prevent unauthorized domain-wide policy changes (DevMan 2.0 uses GPO for mass deployment)
- Monitor for SMB lateral movement patterns consistent with DevMan (Restart Manager API calls, admin share enumeration)
- Deploy behavioral detection rules for Conti/DragonForce/DevMan ransomware lineage patterns (see detections)
- Conduct BYOVD (Bring Your Own Vulnerable Driver) defense: driver allowlist enforcement to block kernel-level security tool termination
- Evaluate MDR vendor security posture, background check programs, and insider threat detection capabilities before renewing or expanding contracts
Weaknesses (CWE) in Alleged Huntress Insider Leaked Law Enforcement
CWE-506, CWE-312, CWE-284, CWE-522
Timeline of Alleged Huntress Insider Leaked Law Enforcement
- Conti v3 ransomware source code leaked publicly, seeding a generation of derivative ransomware families including DragonForce and ultimately DevMan.
- DragonForce ransomware began claiming victims on its leak site, initially using a LockBit 3.0 builder before transitioning to a modified Conti v3 codebase.
- DragonForce released an updated strain based on Conti v3 source code, adding BYOVD (Bring Your Own Vulnerable Driver) capability for kernel-level security tool termination and ChaCha8 encryption for improved performance.
- DragonForce rebranded as a 'cartel' offering a Dragons-as-a-Service affiliate model, allowing affiliates to white-label payloads, create branded variants, and operate under DragonForce infrastructure with full TOR hosting and leak site access.
- DevMan emerged as a new ransomware threat actor, initially operating as an affiliate of both Qilin (Agenda) and DragonForce. First victim — French transport company 'doumen' — claimed via X (Twitter). DevMan payloads confirmed as built using DragonForce builder, inheriting Conti v3 code.
- DevMan expanded to 12-13 victims in May 2025, rising to among the top-tier ransomware groups that month. Notable attacks included a National Social Security Fund (2.5 TB exfiltrated, $2.5M ransom) and a Thai media outlet (170 GB stolen).
- Security researcher GangExposed publicly doxed alleged DevMan operator identities, causing temporary affiliate abandonment. DevMan operations continued despite the disruption.
- ANY.RUN published forensic analysis of DevMan payloads, confirming DragonForce/Conti lineage, documenting the critical builder flaw causing self-encryption of ransom notes, and detailing the AES-256/RSA-2048 hybrid encryption scheme and mutex string hsfjuukjzloqu28oajh727190.
- DevMan split from DragonForce, launching 'DevMan's Place' as an independent TOR-hosted leak site. DevMan operators publicly stated 'we stopped using DragonForce months ago.'
- DevMan launched DevMan 2.0 — a full RaaS platform featuring Rust-written encryptors for Windows, Linux/NAS, and ESXi; a web-based affiliate dashboard; GPO-based domain-wide deployment capability; strict affiliate vetting ($10,000 deposit, prior RaaS experience, 100+ GB proof-of-compromise); and tiered revenue sharing (7-22% depending on target revenue). By this point DevMan had approximately 70-86 confirmed victims.
- Ben Folland, then a Huntress security operations analyst, alleged he discovered evidence that a current Huntress employee was passing US law enforcement (FBI) communications to DevMan ransomware operators.
- DevMan targeted healthcare sector with attacks on Abdulhadi Hospital (246 GB exfiltrated, $350K ransom) and Easter Seals (236 GB exfiltrated, $90K ransom), demonstrating willingness to attack healthcare despite stated prohibition on 'child-related healthcare' targets.
- DevMan confirmed additional victims in February 2026: Crystal Coast Pain Management (North Carolina), Encompass Inc. (Minnesota), and Westervelt Johnson Nicoll & Keller LLC (Illinois), bringing total confirmed victims past 120.
- Ben Folland resigned from Huntress citing irreconcilable conflict of interest related to the alleged insider incident. Huntress later confirmed a former employee raised concerns about a teammate's communications with a cybercriminal.
- Ben Folland publicly alleged the Huntress insider incident via social media. The Register covered the story. Folland promised to publish supporting evidence including FBI correspondence, direct Huntress-employee-to-DevMan messages, recorded phone calls, internal memos, and evidence of threats against himself and his family. Huntress CEO Kyle Hanslovan issued a Reddit response acknowledging 'poor judgment in communicating with a cybercriminal' while disputing the insider framing and citing active law enforcement coordination.
Sources cited for Alleged Huntress Insider Leaked Law Enforcement
- Ex-Huntress analyst claims company insider fed info to a ransomware crim, social media drama ensues
- DevMan Ransomware Analysis: New DragonForce Variant (ANY.RUN)
- DevMan Ransomware Analysis of New DragonForce Variant (ANY.RUN Medium)
- DEVMAN — New DragonForce Ransomware Variant (Broadcom Security Center)
- DragonForce Ransomware Variant Tied to Emerging DevMan Threat Actor (SC World)
- DevMan Threat Group Profile (Halcyon)
- DevMan RaaS Launch — The Affiliate Who Aims to Become the Boss (Analyst1)
- From Conti to Black Basta to DevMan: The Endless Ransomware Rebrand (Vectra AI)
- New DevMan Ransomware by DragonForce (GBHackers)
- Qilin Tops April 2025 Ransomware Report — DevMan Emerges (Cyble)
- DevMan Ransomware Group Analysis 2026 (Ransom-DB)
- Insider Threats in Cybersecurity — Huntress Analyst Claims (CyPro)
- Former Huntress Analyst Alleges Insider Misconduct and Concealment of Security Incident (QPulse)
- DragonForce Ransomware Cartel vs. Everybody (Barracuda Networks)
- Ransomware Spotlight: DragonForce (Trend Micro)
Threats related to Alleged Huntress Insider Leaked Law Enforcement
- Alleged Insider Threat at Huntress: Analyst Accuses Employee of Leaking US Law-Enforcement Communications to DevMan Ransomware Operator
- DevMan RaaS ("Funky Mantis") Centralizes Payload Builds, Victim Management, and Affiliate Payouts, Develops SCADA-Destructive Locker
- DarkCloud Infostealer — Commercial VB6 Credential-Harvesting Malware (A310Logger/BluStealer Successor)
Detection coverage for TL-2026-0970
As of 2026-06-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0970 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-0970
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.