DevMan RaaS ("Funky Mantis") Centralizes Payload Builds, Victim Management, and Affiliate Payouts, Develops SCADA-Destructive Locker — Threadlinqs Intelligence
As of 2026-07-25, DevMan RaaS ("Funky Mantis") Centralizes Payload Builds, Victim Management, and Affiliate Payouts, Develops SCADA-Destructive Locker is a critical-severity ransomware threat attributed to DevMan, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 19 indicators of compromise.
Threat ID: TL-2026-1680 · Severity: CRITICAL · Status: ACTIVE · Category: RANSOMWARE
Attribution: DevMan · FINANCIAL
DevMan, tracked by PRODAFT as "Funky Mantis", is a DragonForce/Conti-lineage ransomware-as-a-service platform whose v3 portal (Jan 2026) centralizes payload builds, victim lifecycle management,
DevMan is a closed ransomware-as-a-service (RaaS) operation that emerged in April 2025 as an affiliate program working under Qilin, DragonForce, Apos, and RansomHub before evolving into an independent, DragonForce-derived lineage ("unmistakably DragonForce" per Vectra AI) with acknowledged Conti operator collaboration from October 2025. PRODAFT's Catalyst intelligence unit tracks the operation under the internal codename "Funky Mantis" and has identified operator handles LARVA-367 (administrator/owner), LARVA-546 (access coordinator), LARVA-547 and LARVA-548 (senior operators/coordinators), and LARVA-550 (affiliate/operator).
The group's core differentiator is a formal, browser-based affiliate portal that unifies payload generation, victim records with lifecycle states, per-victim build configuration, deadline tracking, revenue and financial tracking, team creation, shared operational access, victim chat, and a help desk. Version 1-2 of the portal (through December 2025) covered builders, finance, victim chat, support, and program rules; the January 2026 v3 release added structured victim records, lifecycle states, team creation, per-victim build options, deadline tracking, revenue fields, and shared operational access -- indicating significant operational maturation typically associated with larger, better-resourced RaaS operations (DragonForce, Qilin, RansomHub class).
Technically, the ransomware locker (available for Windows, VMware ESXi, and Linux, with a SCADA-specific variant in development) uses multi-threaded ChaCha20-Poly1305 encryption per PRODAFT's most recent locker analysis, while earlier builder generations (v1.0 C++, v2.0 Rust rewrite) analyzed independently by ANY.RUN and Halcyon used a hybrid AES-256 (CBC) + RSA-2048 asymmetric scheme with full, header-only, and custom encryption modes. Files at or below 3 MiB are fully encrypted; files above 3 MiB receive partial/intermittent encryption (roughly 1 MiB encrypted per 51 MiB) to accelerate large-scale encryption runs. The locker abuses the Windows Restart Manager API (writing to HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000) -- a technique inherited from the Conti lineage -- to release file locks held by active processes, enabling encryption of files in use. Pre-encryption behavior includes privilege-escalation verification, security-control impairment (AV/EDR termination), process/service termination, Volume Shadow Copy and backup/recovery inhibition, Windows Event Log clearing, local and network-share discovery, lateral movement, and optional self-deletion after completion.
Intrusion tradecraft observed across the DevMan/Funky Mantis affiliate base includes phishing with malicious attachments, RDP brute-forcing, and exploitation of edge-facing applications for initial access; BloodHound for Active Directory attack-path mapping and SoftPerfect Network Scanner plus SMB share enumeration for discovery; Mimikatz for LSASS credential dumping alongside a custom infostealer targeting Chrome/Firefox stored credentials; PsExec over admin shares, RDP with stolen credentials, and GPO deployment from compromised domain controllers for lateral movement and privilege escalation; and a largely offline operational model with minimal external C2 beaconing, TOX encrypted messaging for victim/affiliate communication, and dedicated Tor (.onion) leak sites with countdown timers for double-extortion pressure. Exfiltrated data volumes typically range 50GB-300GB (maximum documented 2.5TB), commonly staged to Mega.nz ahead of encryption (data-exfiltration-first methodology).
The affiliate economics follow an 80/20 revenue split in the affiliate's favor, paid out via two separate cryptocurrency wallets (affiliate wallet and RaaS-program wallet). Affiliates are only admitted to the operation's corporate chat after producing a first victim, are removed after one month without a new victim, and require curator approval to form teams or disclose program affiliation; m
Target sectors: technology, health, financial services, professional services, government administration, manufacturing, business services, telecoms, retail, construction, critical infrastructure, industrial control systems
Target regions: united states of america, Asia-Pacific, taiwan, thailand, china, japan, singapore, Africa, kenya, south africa, Latin America, mexico
Detections & IOCs
As of 2026-08-25, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 19 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
RANSOMWARE, CRITICAL, threat intelligence, cybersecurity, T1566, T1078, T1190, T1003, T1555, T1018, T1135, T1482, T1021, T1484