DevMan is a Russia-linked ransomware and ransomware-as-a-service operation that emerged publicly in April 2025 and became notable for combining its own extortion brand with a centrally administered affiliate platform. The operation has also been tracked under the name Funky Mantis. It is associated with aliases including devman_ransomware and devman_ransomware_group. DevMan evolved from affiliate activity tied to other ransomware ecosystems into an independent RaaS program. Reporting consistently links its malware lineage and operational tradecraft to DragonForce, with additional references to code derived from leaked Conti source code. Security reporting has also noted overlap with Qilin-related affiliate activity. Later technical reporting identified strong similarities between DevMan and the subsequently emerged Vect operation, including builder strings, ransom-note structure, and lateral movement naming conventions, suggesting possible operator continuity, rebranding, or shared development, though that relationship is not conclusively established. The group operates a dedicated affiliate portal that supports payload generation, victim tracking, negotiation management, earnings oversight, team administration, and payout handling. Reported governance of the program is comparatively strict: affiliates are curated, assigned support personnel, expected to complete operations within short time windows, and can be removed for inactivity or poor performance. Revenue sharing has been reported at 80 percent to affiliates and 20 percent to core operators. The platform has supported lockers for Windows, Linux, and ESXi environments. Technical analysis of DevMan ransomware indicates capabilities typical of mature enterprise-targeting lockers. Reported functions include privilege checks, impairment of security controls, termination of processes and services, inhibition of recovery mechanisms, event log clearing, discovery of local and network resources, lateral movement support, multi-threaded encryption, ransom-note deployment, and optional self-deletion. Encryption has been described as using ChaCha20-Poly1305, with partial encryption logic for larger files. Public reporting also describes DevMan as maintaining a high-profile extortion presence, publishing victim claims and operational commentary in English and sometimes Russian. Victimology indicates broad, financially motivated targeting across multiple regions, with a significant concentration of claimed victims in the United States and additional activity across Asia, Africa, Europe, and Latin America. Reported sector focus includes technology, healthcare, financial services, professional services, government, and other enterprise environments. DevMan has been associated with attacks against public-sector and critical-service organizations, and its affiliate rules reportedly explicitly encouraged attacks on critical infrastructure outside excluded geographies. DevMan has made claims about specialized operational technology and SCADA-focused encryption capabilities, but those assertions are not well corroborated. Independent OT-focused analysis found no evidence that the group possessed genuine ICS-aware ransomware or the ability to directly manipulate industrial control equipment, and assessed some of its OT-related messaging as exaggeration intended to increase extortion pressure. The operation has also been linked to internal disruption and exposure. A whistleblower reportedly publicized operator identities in mid-2025, contributing to affiliate attrition. Separate reporting tied a decline in DevMan activity in early 2026 to law-enforcement pressure, including the addition of an operator known as Tramp to an Interpol wanted list. Multiple ransomware landscape reports observed that DevMan activity dropped sharply by Q1 2026, and some tracking indicated no new victims after early February 2026. Overall, DevMan is best characterized as a 2025-era Russia-linked RaaS operation with strong ties to the DragonForce and broader post-Conti ransomware ecosystem, notable for structured affiliate management, multi-platform locker support, aggressive public extortion, and broad enterprise and government targeting.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operating a centrally administered ransomware-as-a-service platform with affiliate management, payload building, victim chat, payout handling, access brokerage/distribution, and support for Windows, ESXi, and Linux lockers. The group also promotes attacks on critical infrastructure and offers a separate SCADA encryptor.
Named ransomware operator allegedly received sensitive law-enforcement-related information from a Huntress employee; described as using code derived from the leaked Conti source.
Ransomware operator discussed in connection with communications from a Huntress employee who allegedly disclosed that law enforcement was investigating him.
Ransomware operation discussed in connection with alleged communications from a Huntress employee and described as actively and publicly targeting the former employee and his family.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.