DevMan-Funky Mantis ecosystem shift changes threat-actor operations
Threat Actor Meta
Summary
Hide ▲
Show ▼
DevMan has consolidated its RaaS affiliate portal, tightening control over payload creation, victim handling, and payouts across its criminal service network. PRODAFT tracks the operation as Funky Mantis, and the portal's v3 update in January 2026 added structured victim records, lifecycle states, team controls, deadline tracking, and revenue fields. The platform also bundles build generation, finance, victim chat, support, and access brokerage, giving administrators more leverage over affiliate activity and attack tempo. That structure reduces affiliate autonomy and helps the operators scale multi-victim extortion while steering attacks toward targets outside the CIS and Serbia and toward SCADA-related operations.
Related Happenings
DevMan ransomware locker capability update for Windows, ESXi, and Linux
Malware Activity
H score38
First: 25.07.2026 12:53
Last: 25.07.2026 12:53
Sources 1
How related:
The latest version of the portal allows affiliates to create a locker for Windows, ESXi, or Linux. An analysis of the Windows version has identified functions related to privilege checking to determine if it's running as an administrator, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion.
About this happening:
The DevMan ransomware locker now supports payload builds for Windows, ESXi, and Linux, expanding the operation's reach across server and workstation environments. Analysis...
DevMan ransomware locker capability update for Windows, ESXi, and Linux
Malware ActivityHow related: The latest version of the portal allows affiliates to create a locker for Windows, ESXi, or Linux. An analysis of the Windows version has identified functions related to privilege checking to determine if it's running as an administrator, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion.
About this happening: The DevMan ransomware locker now supports payload builds for Windows, ESXi, and Linux, expanding the operation's reach across server and workstation environments. Analysis...
VenomStealer ecosystem shift changes threat-actor operations
Threat Actor Meta
H score27
First: 31.03.2026 17:51
Last: 31.03.2026 17:51
Sources 1
About this happening:
VenomStealer is being run as a licensed underground service with an affiliate program, shifting it from a single malware kit into a repeatable operator ecosystem that...
VenomStealer ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: VenomStealer is being run as a licensed underground service with an affiliate program, shifting it from a single malware kit into a repeatable operator ecosystem that...
Contagious Interview cryptocurrency social-engineering and malware-delivery campaign
Campaign
H score37
First: 23.03.2026 20:09
Last: 23.03.2026 20:09
Sources 1
About this happening:
A North Korean cluster behind Contagious Interview / WaterPlum is running a coordinated malware campaign against cryptocurrency professionals, increasing the risk...
Contagious Interview cryptocurrency social-engineering and malware-delivery campaign
CampaignAbout this happening: A North Korean cluster behind Contagious Interview / WaterPlum is running a coordinated malware campaign against cryptocurrency professionals, increasing the risk...
Havoc Demon payload deployment and persistence operation
Malware Activity
H score22
First: 03.03.2026 19:15
Last: 03.03.2026 19:15
Sources 1
About this happening:
A fake IT support operation is deploying Havoc Demon payloads to preserve access across compromised endpoints and support likely data exfiltration or ransomware fo...
Havoc Demon payload deployment and persistence operation
Malware ActivityAbout this happening: A fake IT support operation is deploying Havoc Demon payloads to preserve access across compromised endpoints and support likely data exfiltration or ransomware fo...
GrayBravo expands CastleLoader into a multi-cluster malware-as-a-service ecosystem
Threat Actor Meta
H score52
First: 09.12.2025 18:01
Last: 09.12.2025 18:01
Sources 1
About this happening:
GrayBravo has expanded CastleLoader into a malware-as-a-service (MaaS) ecosystem that now includes CastleBot and custom CastleRAT variants, widening access to...
GrayBravo expands CastleLoader into a multi-cluster malware-as-a-service ecosystem
Threat Actor MetaAbout this happening: GrayBravo has expanded CastleLoader into a malware-as-a-service (MaaS) ecosystem that now includes CastleBot and custom CastleRAT variants, widening access to...
Timeline
-
25.07.2026 12:53 2 articles · 2h ago
DevMan-Funky Mantis ecosystem shift changes threat-actor operations
Initial DisclosureIn April 2025, DevMan emerged as an affiliate tied to Qilin, DragonForce, Apos, and RansomHub before moving toward its own dedicated service. By January 2026, the operation had a centralized portal and governance structure that formalized affiliate workflows.
Show sources
- DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts — thehackernews.com — 25.07.2026 12:53
- DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts — thehackernews.com — 25.07.2026 12:53