The record
Written from the 1 report below. Nothing here is unsourced.
- Swiss cybersecurity firm PRODAFT has released a detailed report on the DevMan ransomware-as-a-service operation, which it tracks under the name Funky Mantis.
- The report describes an upgraded affiliate portal (v3, released January 2026) that supports payload building, earnings management, victim tracking, team creation, and payout functions, formalizing how affiliates run attacks.
- DevMan first appeared in April 2025 as an affiliate of groups like Qilin, DragonForce, and RansomHub before launching its own program, and has claimed 184 victims, nearly 50 of them in the U.S., with no new victims reported after February 4, 2026.
- The operation also faces insider threat allegations involving a former Huntress employee, and was previously disrupted in June 2025 when a whistleblower known as GangExposed doxxed operator identities.
What to watch next
- Whether DevMan resumes claiming new victims after the lull following February 4, 2026
- Developments in the insider threat allegations involving a former Huntress employee
- Further use or escalation of the claimed specialized SCADA locker targeting industrial control systems
Coverage1
1 report
English national1
All filed from India
Named United States · Israel · Huntress · Ben Folland · Conti · DevMan · FBI · Federal Bureau of Investigation · GangExposed · Israel National Cyber Directorate · Jon DiMaggio · Kyle Hanslovan · PRODAFT · Qilin
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
