Skip to content

Devman

DevMan is a ransomware family associated with a financially motivated operation that emerged publicly in April 2025.

Devman

Family profile

DevMan is a ransomware family associated with a financially motivated operation that emerged publicly in April 2025. Its operators previously participated in ransomware affiliate programs including Qilin, APOS, DragonForce, and RansomHub before establishing their own ransomware-as-a-service operation. The operation, tracked by PRODAFT as Funky Mantis, maintains an affiliate platform for payload generation, victim management, negotiations, team coordination, and revenue tracking. Later versions offer lockers for Windows, Linux, and VMware ESXi, with integrated access distribution and victim-specific build options.

DevMan encompasses builds with differing codebases and encryption implementations. An early analyzed build substantially reused DragonForce's Conti-derived code, while another shared substantial code with Mamona. A Windows sample used per-file Curve25519 ECDH key agreement, Blake2-based key derivation, and HC-256 encryption, with configurable partial encryption for larger files. Later Windows locker analysis identified ChaCha20-Poly1305 encryption and intermittent processing of large files. Builds support multithreaded encryption, configurable local and network targets, delayed or scheduled execution, and optional password-protected execution.

Windows capabilities include network-share discovery, SMB-based probing, credential-assisted LDAP-domain spreading, process and service termination, security-tool impairment, shadow-copy deletion, event-log clearing, and optional self-deletion. Some builds use runtime API hashing and encrypted configuration data. DevMan creates ransom notes and can change desktop wallpaper or print ransom demands. Its extortion operation threatens publication of stolen data, although an analyzed Windows payload had no identified built-in data-exfiltration capability.

DevMan has targeted organizations across technology, healthcare, financial services, professional services, government, transport, and industrial sectors. Its affiliate policies explicitly encourage critical-infrastructure attacks and restrict targeting of CIS countries and Serbia.

Capabilities

  • Defense Evasion
  • Extortion
  • Lateral Movement
  • Reconnaissance
  • Scanning

Samples

Recent samples

1 sandbox sample in the Derp library, newest 1 shown

Reported operators

Threat actors

4 named in public reporting
Devman

DevMan has become more independent and claimed to use their own ransomware, eponymously named “DevMan”.

Funky Mantis

The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims.

Tramp

Devman declined by 70%, from 82 victims to 25. The ransomware’s operator “Tramp”, a former Conti and Black Basta affiliate, was added to Interpol’s wanted list in January 2026.

DragonForce

“Security researchers have reportedly identified Devman ransomware payloads that are build on DragonForce infrastructure.”

MITRE ATT&CK

Devman in ATT&CK

11 distinct techniques

Reporting

Research mentioning Devman

Jul 25
The Hacker News

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

Researchers say DevMan, also tracked as Funky Mantis, operated a centralized ransomware-as-a-service platform with a dedicated affiliate portal for payload generation, victim management, ransom negotiation, earnings tracking, and internal coordination. PRODAFT reported the group was active from late 2025 into early 2026, used an 80/20 affiliate revenue split, and claimed 184 victims, with the heaviest concentration in the United States across technology, healthcare, financial services, professional services, and government. The operation explicitly pursued hospitals, critical infrastructure, the public sector, and law enforcement, and advertised a separate encryptor for SCADA environments, underscoring its focus on high-impact targets. Technical reporting links DevMan’s malware to DragonForce/Conti lineage while showing the operation evolved beyond a simple variant. Earlier analysis described a DragonForce-based sample marked by the .DEVMAN extension, SMB share probing, rapid encryption, and a builder flaw that encrypted its own ransom notes; later reporting identified a Rust-based Devman Locker using ChaCha20-Poly1305, appending .devman21, dropping RESTORE_FILES.txt, mounting network shares, disabling defenses, deleting shadow copies and event logs, and inhibiting recovery. The latest portal version reportedly supports Windows, Linux, and ESXi lockers and includes features for privilege checks, lateral movement, and security-tool impairment, indicating a mature and centrally managed extortion operation.

Jul 23
Cyberveille

Funky Mantis (DevMan) : analyse complète d'un RaaS centralisé ciblant hôpitaux et infrastructures critiques | CyberVeille