DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims.
Intelligence analysis by Llama

The DevMan RaaS portal has been upgraded to version 3, which includes features such as structured victim records, life cycle states, team creation, and shared operational access. The portal is used by affiliates to manage their operations and communicate with each other.
Imagine a group of people working together to steal money from companies by encrypting their files. They have a special website where they can share information and work together to make it easier to steal money. This website is like a headquarters for the group, and it helps them to be more organized and efficient in their attacks.
Analysis
A Centralized Ransomware Operation
The DevMan RaaS portal is a significant development in the world of ransomware, as it centralizes the operations of affiliates and provides them with a range of tools to manage their activities. This could lead to a more organized and efficient ransomware operation, making it more difficult for victims to recover from attacks.
The portal was first identified by Swiss cybersecurity company PRODAFT, which has been tracking the centrally administered RaaS operation under the name Funky Mantis. According to PRODAFT, the portal offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims.
A Formalized Affiliate Workflow
The DevMan RaaS portal has been upgraded to version 3, which includes features such as structured victim records, life cycle states, team creation, and shared operational access. This progression indicates an effort to formalize affiliate workflows and manage multiple intrusions through a common platform rather than relying only on chat-based coordination.
Governance Model
The core management of the DevMan RaaS operation reserves the right to take over a conversation if an affiliate behaves inappropriately or fails to adhere to a commitment. The governance model reduces affiliate autonomy, while giving the administrators the power to enforce operational tempo and protect their revenue.
Targeting Policy
DevMan's stated targeting policy allows affiliates to strike entities outside the CIS countries and Serbia. It also excludes CIS consulates and CIS-linked companies, and lifts a previous restriction on Saudi Arabia. Besides explicitly encouraging attacks against critical infrastructure, it instructs affiliates to request a separate encryptor for SCADA systems, corroborating their development on a specialized SCADA locker.
Key points
- The DevMan RaaS portal is a centralized platform for affiliates to manage their operations and communicate with each other.
- The portal includes features such as structured victim records, life cycle states, team creation, and shared operational access.
- The core management of the DevMan RaaS operation reserves the right to take over a conversation if an affiliate behaves inappropriately or fails to adhere to a commitment.
- DevMan's stated targeting policy allows affiliates to strike entities outside the CIS countries and Serbia.
- The operation has a governance model that reduces affiliate autonomy and gives administrators the power to enforce operational tempo and protect their revenue.
If the DevMan RaaS operation is disrupted or shut down, it could lead to a decrease in ransomware attacks and a reduction in the amount of money stolen from companies. This could also lead to a decrease in the number of people affected by ransomware attacks, as the operation is centralized and easier to target.
If the DevMan RaaS operation is not disrupted or shut down, it could lead to a continued increase in ransomware attacks and a continued reduction in the amount of money stolen from companies. This could also lead to a continued increase in the number of people affected by ransomware attacks, as the operation is centralized and easier to target.



