Skip to content
feed: live
>_ 0dayNews
ransomware
● Breaking

DevMan RaaS Offers Affiliates Centralized Build Portal

PRODAFT documents DevMan RaaS — tracked as Funky Mantis — operating a unified portal for payload builds, victim management, and affiliate payouts.

DevMan RaaS Offers Affiliates Centralized Build Portal
Photo: screenshot of Motormille2 / Wikimedia Commons · Public domain
airgap airgap · Published · 2 min read

New RaaS operation documented. Confirmed active. Swiss threat intelligence firm PRODAFT has identified and is tracking the DevMan ransomware-as-a-service scheme under the internal codename Funky Mantis.

What PRODAFT documented. The operation runs a centralized web portal purpose-built for affiliates. Three integrated functions: payload builder (affiliates configure and generate customized ransomware binaries), financial management (commission tracking, ransom proceeds), and victim case management (status, extortion coordination). That’s the full affiliate workflow consolidated into a single interface. Reported by The Hacker News, July 25.

Why this matters structurally. Unified affiliate portals lower the operational floor for ransomware operators. Earlier RaaS ecosystems stitched together separate build infrastructure, payment channels, and communication panels — more complexity, more failure points, more operational drag. An integrated platform reduces overhead per affiliate, accelerates onboarding, and produces more consistent campaign execution across operators. The criminal business model is maturing in the same direction legitimate SaaS has: consolidate the workflow, reduce churn.

What is not yet confirmed. Targeted industries, active victim count, current ransom demand ranges, specific malware behavioral characteristics, and indicators of compromise are not in PRODAFT’s public disclosure at time of writing. Treat any sector-specific attribution circulating before their full technical report as unconfirmed — treat accordingly.

Confidence: PRODAFT observation and tracking confirmed. “Funky Mantis” is PRODAFT’s designation; the operators’ self-identification is not yet public. Full technical indicators pending PRODAFT’s formal release.

Defender checklist, in priority order.

  1. Watch for PRODAFT’s full technical disclosure on Funky Mantis — indicators of compromise and behavioral signatures will surface there first. Subscribe to your ISAC feed for the release.
  2. Verify EDR and NDR signature coverage is current and telemetry is reaching your SIEM before indicators drop. Reactive tuning after an incident is worse than no tuning.
  3. Audit outbound data transfer volumes now. RaaS affiliates operating extortion-first models routinely stage exfiltrated data before deploying encryption; catching abnormal staging traffic is the highest-leverage defensive window.
  4. Confirm offline backup integrity regardless of your sector. Affiliate-driven RaaS means operators adapt tooling to the target environment — don’t assume your backup infrastructure isn’t in scope.

No indicators confirmed public at time of writing. Monitor PRODAFT’s threat research and your sector ISAC for the Funky Mantis release.


Source: The Hacker News, July 25, 2026 / PRODAFT (Funky Mantis tracking)

Found this useful? Share it.