DevMan is a Russia-linked ransomware-as-a-service operation that emerged in 2025 and is also tracked by some researchers as Funky Mantis. It evolved from affiliate activity associated with other ransomware brands into a centrally administered extortion platform with dedicated affiliate tooling for payload generation, victim management, negotiations, team coordination, and revenue sharing. Reporting links its malware lineage to DragonForce and to code derived from leaked Conti sources, with some assessments describing modified DragonForce code built on top of Conti-derived components. DevMan has also been discussed as associated with the broader DragonForce ecosystem. The operation uses a mature affiliate model with governance controls, curated onboarding, access-brokerage support, and an affiliate-favorable revenue split. Its platform has supported lockers for Windows, Linux, and ESXi environments. Documented functionality includes privilege checks, impairment of security controls, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, ransom-note deployment, and multi-threaded file encryption using ChaCha20-Poly1305. DevMan has publicly promoted attacks against critical infrastructure and claimed to possess a separate SCADA-focused encryptor, although at least some industrial-control claims have been assessed as exaggerated and unsupported by evidence of genuine ICS interaction. DevMan is a double-extortion actor that combines encryption with data theft and operates a leak site to pressure victims. It has claimed victims across multiple continents, with the largest concentration in the United States and notable activity in government, technology, healthcare, and financial services, as well as professional services. Publicly reported victim countries include the United States, Spain, Kenya, Thailand, Singapore, China, and Georgia. The group has been tied to high-value ransom demands and to attacks against public-sector entities, including social security and court-related organizations. The actor maintained a high-profile public presence, posting in English and sometimes Russian, publishing operational write-ups, and aggressively marketing its service. Its known aliases include devman, devman_ransomware, and devman_ransomware_group. Some reporting identifies an operator known as Tramp, described as a former Conti and Black Basta affiliate. By early 2026, DevMan activity declined sharply and then appeared to go dormant, with later reporting noting strong technical and operational overlaps between DevMan and the emerging Vect ransomware operation, raising the possibility of operator continuity or rebranding, though that linkage is not conclusively established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operating a centrally administered ransomware-as-a-service platform with affiliate management, payload building, victim chat, payout handling, access brokerage/distribution, and support for Windows, ESXi, and Linux lockers. The group also promotes attacks on critical infrastructure and offers a separate SCADA encryptor.
Named ransomware operator allegedly received sensitive law-enforcement-related information from a Huntress employee; described as using code derived from the leaked Conti source.
Ransomware operator discussed in connection with communications from a Huntress employee who allegedly disclosed that law enforcement was investigating him.
Ransomware operation discussed in connection with alleged communications from a Huntress employee and described as actively and publicly targeting the former employee and his family.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.