discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims.

By Ravie Lakshmanan·Jul 25·thehackernews.com·2 min read

Intelligence analysis by Llama

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
Image: thehackernews.com

The DevMan RaaS portal has been upgraded to version 3, which includes features such as structured victim records, life cycle states, team creation, and shared operational access. The portal is used by affiliates to manage their operations and communicate with each other.

Why it matters

The DevMan RaaS portal is a significant development in the world of ransomware, as it centralizes the operations of affiliates and provides them with a range of tools to manage their activities. This could lead to a more organized and efficient ransomware operation, making it more difficult for victims to recover from attacks.

Imagine a group of people working together to steal money from companies by encrypting their files. They have a special website where they can share information and work together to make it easier to steal money. This website is like a headquarters for the group, and it helps them to be more organized and efficient in their attacks.

Analysis

A Centralized Ransomware Operation

The DevMan RaaS portal is a significant development in the world of ransomware, as it centralizes the operations of affiliates and provides them with a range of tools to manage their activities. This could lead to a more organized and efficient ransomware operation, making it more difficult for victims to recover from attacks.

The portal was first identified by Swiss cybersecurity company PRODAFT, which has been tracking the centrally administered RaaS operation under the name Funky Mantis. According to PRODAFT, the portal offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims.

A Formalized Affiliate Workflow

The DevMan RaaS portal has been upgraded to version 3, which includes features such as structured victim records, life cycle states, team creation, and shared operational access. This progression indicates an effort to formalize affiliate workflows and manage multiple intrusions through a common platform rather than relying only on chat-based coordination.

Governance Model

The core management of the DevMan RaaS operation reserves the right to take over a conversation if an affiliate behaves inappropriately or fails to adhere to a commitment. The governance model reduces affiliate autonomy, while giving the administrators the power to enforce operational tempo and protect their revenue.

Targeting Policy

DevMan's stated targeting policy allows affiliates to strike entities outside the CIS countries and Serbia. It also excludes CIS consulates and CIS-linked companies, and lifts a previous restriction on Saudi Arabia. Besides explicitly encouraging attacks against critical infrastructure, it instructs affiliates to request a separate encryptor for SCADA systems, corroborating their development on a specialized SCADA locker.

Key points

  • The DevMan RaaS portal is a centralized platform for affiliates to manage their operations and communicate with each other.
  • The portal includes features such as structured victim records, life cycle states, team creation, and shared operational access.
  • The core management of the DevMan RaaS operation reserves the right to take over a conversation if an affiliate behaves inappropriately or fails to adhere to a commitment.
  • DevMan's stated targeting policy allows affiliates to strike entities outside the CIS countries and Serbia.
  • The operation has a governance model that reduces affiliate autonomy and gives administrators the power to enforce operational tempo and protect their revenue.
The Upside

If the DevMan RaaS operation is disrupted or shut down, it could lead to a decrease in ransomware attacks and a reduction in the amount of money stolen from companies. This could also lead to a decrease in the number of people affected by ransomware attacks, as the operation is centralized and easier to target.

The Downside

If the DevMan RaaS operation is not disrupted or shut down, it could lead to a continued increase in ransomware attacks and a continued reduction in the amount of money stolen from companies. This could also lead to a continued increase in the number of people affected by ransomware attacks, as the operation is centralized and easier to target.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagsransomwarecybercrimedevmanraasportalaffiliatepayouts

Author

Ravie Lakshmanan

Intelligence analysis by

Llama

Published

Jul 25, 2026

Source

thehackernews.com

Share

Topics

ransomwarecybercrimedevmanraasportalaffiliatepayouts

Related

More from this desk

Jul 25·thehackernews.com

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

Phishing campaigns targeting financial institutions have evolved, with attackers now synchronizing their activity with victims in real-time, authenticating against legitimate insurance portals as victims unknowingly complete the login process.

Jul 25·thehackernews.com

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Threat actors linked to the Cl0p ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign.

Jul 25·bleepingcomputer.com

OpenAI confirms ChatGPT is down worldwide

OpenAI's ChatGPT is experiencing a major outage, affecting users worldwide. The outage started at approximately 5 AM ET and is causing 'too many concurrent requests' errors. OpenAI is aware of the issue and has acknowledged it on their status page.

Jul 25·thehackernews.com

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

A security researcher has published a working proof-of-concept (PoC) exploit that executes commands as git on an unpatched self-managed GitLab 18.11.3 server. The exploit is build-specific to GitLab 18.11.3 on x86-64 and affects broader releases.