DevMan, also tracked as Funky Mantis, is a Russia-linked, financially motivated ransomware operation that emerged publicly in April 2025. It initially operated as an affiliate of Qilin, APOS, and DragonForce before establishing its own ransomware-as-a-service platform in 2025. Its ransomware has a documented code lineage associated with DragonForce and leaked Conti source code. DevMan targets organizations internationally, particularly in technology, healthcare, financial services, professional services, and government. Its victims also include transportation and media organizations, with the United States representing the largest identified national concentration of claimed victims. DevMan conducts double extortion, stealing information before encrypting systems and threatening publication through dedicated data-leak infrastructure. Its operators use public social-media activity to announce compromises, taunt victims, and amplify extortion pressure. Documented harassment includes publishing identifiable HIV test results and threatening further disclosure targeting affected patients. Victim counts published by the operation represent claims rather than independently verified compromises. Its centrally administered affiliate platform integrates access distribution, customized payload generation, victim records, negotiations, team management, support, and payout tracking. The platform supports Windows, Linux, and VMware ESXi lockers. Administrators supervise affiliate activity and can take over victim negotiations. The operation explicitly encourages attacks on critical infrastructure, although claims of specialized industrial-control capabilities are not substantiated. DevMan intrusions use compromised credentials and exposed remote services for initial access, followed by reconnaissance, privilege acquisition, lateral movement, data theft, and widespread encryption. Analyzed Windows lockers support local and network-share discovery, domain spreading, configurable multithreaded encryption, security-process and service termination, event-log clearing, shadow-copy deletion, and optional self-deletion. Encryption implementations vary across samples: an earlier analyzed locker used Curve25519-derived keys with Blake2 and HC-256, while a later locker used ChaCha20-Poly1305. The absence of an embedded exfiltration function in an analyzed encryptor does not negate the operation's documented data-theft and disclosure activities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
17 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operating a centrally administered ransomware-as-a-service platform with affiliate management, payload building, victim chat, payout handling, access brokerage/distribution, and support for Windows, ESXi, and Linux lockers. The group also promotes attacks on critical infrastructure and offers a separate SCADA encryptor.
Named ransomware operator allegedly received sensitive law-enforcement-related information from a Huntress employee; described as using code derived from the leaked Conti source.
Ransomware operator discussed in connection with communications from a Huntress employee who allegedly disclosed that law enforcement was investigating him.
Ransomware operation discussed in connection with alleged communications from a Huntress employee and described as actively and publicly targeting the former employee and his family.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.