DevMan RaaS Platform (Funky Mantis Operation)
First seen Jul 27, 2026 · Updated Jul 27, 2026
DevMan is a ransomware-as-a-service operation running a centralized web portal that lets affiliates build custom payloads, track victim status, and manage payouts. PRODAFT is tracking the broader operator infrastructure under the name Funky Mantis, indicating a structured, business-like criminal enterprise lowering the barrier to entry for ransomware deployment. The centralized tooling suggests active recruitment and scaling of affiliates, increasing the likely volume and diversity of attacks.
Technical Analysis
The DevMan portal functions as a management console enabling affiliates to generate ransomware payload builds on demand, monitor victim negotiation/payment status, and receive automated affiliate commission payouts, mirroring the operational maturity seen in LockBit- and BlackCat-style RaaS ecosystems. This centralization implies the operators maintain a build server and backend infrastructure that could itself be a high-value target for takedown or infiltration, and also indicates standardized encryption routines/payload templates reused across affiliate campaigns. No specific CVEs or initial access vectors were disclosed in this reporting, though RaaS affiliates typically rely on phishing, exposed RDP/VPN, or exploitation of known vulnerabilities in edge devices for initial access. Organizations running AI agent infrastructure should treat this as a general ransomware risk: any host running agent orchestration, RAG pipelines, or LLM tool-execution environments that is compromised via affiliate-deployed payloads could suffer encryption of model artifacts, vector stores, or credential stores (API keys, service tokens) used by agents, disrupting agent operations and exposing secrets to the extortion group.
Affected Systems
Enterprise Windows and Linux servers/endpoints targeted by DevMan affiliates; no specific software versions or CVEs disclosed in current reporting
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) disclosed in the source reporting
Remediation Steps
- 1
Harden external access points
Restrict and monitor RDP, VPN, and other remote access services commonly abused for initial ransomware access; enforce MFA on all remote access.
- 2
Segment and back up critical infrastructure
Ensure offline/immutable backups of systems hosting agent frameworks, model weights, vector databases, and credential stores, and test restoration procedures regularly.
- 3
Deploy EDR/anti-ransomware controls
Use endpoint detection and response tooling capable of detecting mass file encryption behaviors and known ransomware TTPs.
- 4
Rotate and vault agent-related secrets
Store API keys and tokens used by AI agents in a secrets manager with short-lived credentials to limit blast radius if a host is compromised.
- 5
Monitor threat intelligence for DevMan/Funky Mantis IOCs
Track PRODAFT and other vendor reporting for emerging indicators, affiliate TTPs, and negotiation site domains associated with this RaaS operation.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.