Actor Profile

DevMan (tracked as Funky Mantis by PRODAFT) is a ransomware-as-a-service operation that emerged in April 2025, initially as an affiliate for Qilin, DragonForce, Apos, and RansomHub before transitioning to independent RaaS operations. The group maintains a centralized web portal enabling affiliates to build payloads, manage victims, and track earnings. DevMan operators claim prior involvement with Conti and have developed specialized SCADA lockers targeting industrial control systems. The operation suffered disruption in June 2025 when a whistleblower (GangExposed) doxxed operator identities, leading to affiliate defections. PRODAFT has identified five distinct operational roles within DevMan, including administrators (LARVA-367), access coordinators (LARVA-546), and senior operators. The group operates with a high-profile online presence, frequently posting in English and Russian about their achievements and attack methodologies.

TTPs (Tactics, Techniques, Procedures)

DevMan employs a comprehensive RaaS model with integrated access brokerage and centralized affiliate management. The Windows locker variant exhibits multiple MITRE ATT&CK techniques including privilege escalation checks, defense evasion through security-control impairment (T1562), process and service termination (T1489), recovery inhibition (T1490), event log clearing (T1070.001), discovery via local and network-share enumeration (T1135, T1083), lateral movement capabilities, and impact through multi-threaded ChaCha20-Poly1305 encryption (T1486). Files under 3 MiB are fully encrypted while larger files undergo partial encryption. The operation provides Windows, ESXi, and Linux encryptors with optional self-deletion functionality. DevMan integrates access distribution with ransomware deployment, offering country-specific 'networks' and imposing 2-3 day completion windows. The group has developed specialized SCADA lockers designed to push industrial control systems beyond operating parameters, causing progressive physical damage beyond encryption.

Targets & Patterns

DevMan has claimed 184 victims as of February 2026, with nearly 50 located in the United States. Primary targeted sectors include technology, healthcare, financial services, professional services, and government. The group's targeting policy explicitly permits attacks on entities outside CIS countries and Serbia, while excluding CIS consulates, CIS-linked companies, and previously restricted Saudi Arabia (restriction now lifted). DevMan actively encourages attacks against critical infrastructure and provides specialized SCADA encryptors for industrial targets. The policy prohibits attacks on child-related healthcare businesses and intentional leaks of personal data for individuals under 18. The geographic and sectoral distribution suggests opportunistic targeting driven by affiliate access rather than strategic intelligence collection, with emphasis on high-value sectors capable of paying substantial ransoms.

Historical Context

DevMan's ransomware shares DNA with DragonForce, indicating shared lineage or code reuse from that operation. The group emerged in April 2025 as a multi-affiliate operator working with established RaaS programs (Qilin, DragonForce, Apos, RansomHub) before launching independent operations. Operators claim prior involvement with Conti, one of the most prolific ransomware operations before its dissolution. The operation experienced significant disruption in June 2025 when GangExposed publicly doxxed operator identities and allegedly attempted extortion for 0.3-1 Bitcoin, causing affiliate defections. The affiliate portal has evolved through three versions, with v3 released in January 2026 introducing structured victim records, lifecycle states, team management, and formalized workflows. No new victims have been reported after February 4, 2026, suggesting potential operational pause or detection challenges. The progression from affiliate work to independent RaaS operation mirrors patterns seen in other ransomware ecosystems where experienced operators branch out to maximize profits.

Defensive Recommendations

  • Monitor for ChaCha20-Poly1305 encryption activity and implement behavioral detection for multi-threaded file encryption patterns characteristic of DevMan locker (T1486)
  • Detect defense evasion through security control impairment (T1562), process/service termination (T1489), and Windows event log clearing (T1070.001) via EDR and SIEM correlation
  • Implement network segmentation and monitor lateral movement attempts, particularly SMB/network share enumeration (T1135) and unusual access to ESXi/Linux systems
  • Harden SCADA and industrial control systems with strict access controls, network isolation, and anomalous parameter monitoring to detect specialized locker deployment attempts
  • Enforce privilege escalation monitoring and restrict administrative access; detect unauthorized privilege checks and attempts to run ransomware with elevated permissions

---

# Geopolitical Context

Geopolitical Context

The DevMan ransomware-as-a-service operation represents an evolution in cybercriminal business models, demonstrating increasing professionalization of transnational organized crime in cyberspace. The operation's targeting policy—which explicitly excludes Commonwealth of Independent States (CIS) countries and Serbia while encouraging critical infrastructure attacks—is consistent with threat actors operating from or aligned with Russian-speaking jurisdictions. The group's lineage traces to DragonForce and claimed historical ties to the Conti syndicate, which dissolved following Russia's 2022 invasion of Ukraine. DevMan's development of specialized SCADA-targeting capabilities and explicit encouragement of critical infrastructure attacks represents a concerning escalation in ransomware threat profiles, blurring lines between financially motivated cybercrime and potential state-tolerated cyber operations that could serve strategic deterrence or coercive functions.

State Actor Alignment

DevMan's operational security posture and targeting restrictions are consistent with threat actors operating within or enjoying safe harbor in Russian-speaking jurisdictions. The explicit exclusion of CIS member states, Serbia, CIS consulates, and CIS-linked companies from targeting aligns with the tacit understanding between Russian authorities and cybercriminal groups: ransomware operators may conduct attacks against Western targets with impunity provided they avoid domestic victims. The lifting of restrictions on Saudi Arabia may reflect evolving geopolitical calculations. While no direct state sponsorship is evident, the group's claimed Conti lineage links it to an ecosystem that has demonstrated operational overlap with Russian state interests. The development of SCADA-specific malware designed to cause physical damage elevates DevMan beyond typical financially motivated actors, suggesting capabilities that could serve dual-use purposes. Western law enforcement and sanctions regimes have increasingly targeted ransomware infrastructure, though attribution and disruption remain challenging when operators enjoy territorial sanctuary.

Business Impacty pro region

DevMan's operations pose significant risks to European critical infrastructure, particularly given the group's explicit encouragement of attacks against industrial control systems and SCADA environments. Switzerland-based PRODAFT's tracking of the operation underscores European cybersecurity firms' role in threat intelligence production. The United States remains the primary victim geography (nearly 50 of 184 claimed victims), with healthcare, financial services, government, and technology sectors most affected—all designated critical infrastructure under U.S. policy frameworks. The group's apparent operational pause since February 2026 may reflect disruption from the June 2025 doxxing incident or law enforcement pressure, though such pauses have historically proven temporary. European entities face elevated risk given geographic proximity to suspected operator locations and the group's exclusion of only CIS-aligned targets. The specialized SCADA locker represents a particular threat to European energy, manufacturing, and utilities sectors, which have been priority targets for both cybercriminal and state-aligned actors since 2022. Cross-border coordination through Europol, FBI, and allied agencies remains essential for disruption efforts.

Forecast

If DevMan resumes active operations following its apparent February 2026 pause, European critical infrastructure entities—particularly in energy, manufacturing, and utilities sectors—are likely to face elevated targeting risk given the group's SCADA capabilities and exclusion of only CIS-aligned victims. Should the specialized SCADA locker be deployed operationally and cause physical damage as designed, it would likely trigger enhanced law enforcement response and potential attribution efforts by Western intelligence services, given the national security implications of attacks causing kinetic effects. If the doxxing incident and affiliate defections in mid-2025 continue to constrain recruitment, DevMan may consolidate operations with a smaller, trusted affiliate base, potentially reducing victim volume but increasing operational security. Alternatively, if the operation has effectively ceased, former affiliates may migrate to competing RaaS platforms such as RansomHub or emerging successors, dispersing rather than eliminating the threat. Continued development and proliferation of ICS-targeting ransomware capabilities across the cybercriminal ecosystem would represent a strategic escalation, potentially prompting policy responses including expanded sanctions, offensive cyber operations, or enhanced critical infrastructure protection mandates.