# The RaaS Playbook Gets a Product Manager


When security researchers from PRODAFT cracked open the DevMan ransomware operation, they didn't find a gang. They found a software company.


Affiliate onboarding flows. Structured victim records with lifecycle states. Per-victim build options, deadline tracking, revenue fields, invitation controls, and tiered team access — all wrapped inside a versioned portal now on its third major release. The group PRODAFT tracks internally as Funky Mantis has built the kind of operational infrastructure that would look familiar to anyone who's managed a SaaS product. The difference is that the customers are extortion victims, and the product roadmap culminates in encrypted file systems and ransom demands.


This is the new face of ransomware-as-a-service, and DevMan is its clearest expression yet.


## From Affiliate to Operator in Eight Months


DevMan didn't start at the top. The group surfaced in April 2025 as a conventional affiliate — renting infrastructure from Qilin, DragonForce, Apos, and RansomHub and taking a cut of proceeds. That arrangement lasted less than a year before they pivoted to running their own operation.


The transition matters because it's a pattern. Mid-tier ransomware actors absorb operational knowledge from established RaaS platforms, learn what works, then spin out. DevMan's locker code carries what Vectra AI described as an "unmistakably DragonForce" lineage — they didn't just learn the business model, they inherited the codebase.


By January 2026, they shipped portal v3: a fully structured platform handling build generation, finance, victim chat, help desk, team management, and payout functions under one roof. Affiliates were added to corporate group chats after landing their first victim, then assigned an experienced "curator" — essentially a mentor for extortion. Country-specific "networks" were offered. Two-to-three-day completion windows were imposed. This is project management applied to ransomware deployment.


PRODAFT identified five named roles within the operation, labeled LARVA-367 through LARVA-550, covering administrator, access coordinator, two senior operators, and an affiliate. The hierarchy mirrors what you'd see in a legitimate managed services operation, right down to the division between people who source access and people who execute attacks.


## The SCADA Claim That Should Alarm Critical Infrastructure Teams


The most unsettling detail in the DevMan dossier isn't the victim count or the affiliate portal — it's what the operator claimed in an October 2025 interview with security researcher Jon DiMaggio.


DevMan said they developed a specialized SCADA locker targeting a gas company. Not to encrypt data. To cause physical damage. The malware, as described, would push industrial control systems past thermal and operational limits — running processors and hardware hot until components failed. Progressive physical destruction, beyond what encryption alone achieves.


This claim should be treated carefully. Threat actors routinely inflate their capabilities for reputation and leverage. But two things make this worth taking seriously: first, DevMan acknowledged prior Conti affiliation, and Conti-linked operators have historically demonstrated genuine ICS capability. Second, the specificity of the description — processors, memory, thermal limits, graduated escalation — is not how someone with no ICS knowledge describes an attack.


Whether this specific tool was deployed, tested, or remains aspirational is unclear. What is clear: this group was actively recruiting for ICS attack capability and had enough knowledge to describe a plausible attack path against operational technology environments.


Energy sector security teams need to read this carefully.


## The Whistleblower Who Dented the Operation


In June 2025, an account calling itself GangExposed did what law enforcement has struggled to do — disrupted the DevMan operation by publishing operator identities. Several affiliates walked.


The doxxing apparently came with an extortion demand: 0.3 to 1 Bitcoin in exchange for staying quiet. DevMan claims they refused. GangExposed published anyway.


The aftermath is visible in the data. Ransomware.Live shows 184 claimed victims total, but no new victims reported after February 4, 2026. Whether that's operational paralysis, a strategic pause, or genuine shutdown is impossible to say from the outside. But the timeline is suggestive — the doxxing in June 2025, some affiliate defections, and then an apparent operational slowdown culminating in silence by early 2026.


This matters for threat intelligence teams tracking active RaaS operations. DevMan may be dormant. Or they may be rebuilding under a new name, as ransomware actors routinely do after exposure.


## The 184 Victims and Who Got Hit


Nearly 50 of DevMan's 184 claimed victims are in the United States. The sector distribution is the standard ransomware target map: technology, healthcare, financial services, professional services, and government. No surprises there — these sectors hold the combination of valuable data, operational pressure to restore access quickly, and historically inconsistent security posture that makes them reliable ransomware targets.


The healthcare presence is worth flagging separately. Ransomware against hospitals and health systems isn't new, but a group with claimed ICS capability and a track record of targeting multiple sectors adds a threat dimension beyond data encryption.


---


## HackWire Analysis


The DevMan portal documentation reveals something the raw victim counts don't: ransomware operations are maturing faster than defender tooling is adapting to them.


The shift from chat-based coordination to versioned affiliate portals with lifecycle management, team roles, and payout tracking isn't just organizational convenience — it's a force multiplier. When you reduce the friction for affiliates to onboard, execute, and get paid, you increase attack volume. DevMan's v3 portal is essentially a CRM for extortion campaigns. That's the competitive pressure defenders are actually facing.


What most reporting on this story will miss is the implied commoditization of access brokerage. DevMan offered affiliates a choice: bring your own network access or use program-supplied access. This means the operation had established pipelines to compromised infrastructure — initial access already purchased or brokered — waiting to be paired with affiliates ready to deploy ransomware. The attack itself is no longer the bottleneck. Distribution is.


The GangExposed disruption also deserves more analysis than it usually gets. A single actor with doxxing capability produced measurable operational damage — affiliate attrition, apparent slowdown — that law enforcement actions against similarly sized operations have struggled to match. That's not an argument for vigilantism; it's a data point about where ransomware groups are actually vulnerable. Identity exposure, reputational damage within criminal forums, and affiliate confidence are the soft targets. OPSEC failures are where these groups bleed.


Finally, the SCADA claim. Even if DevMan was inflating capability for credibility, the fact that they considered ICS attacks a credential worth advertising means the threat actor market has shifted. OT security teams in energy, utilities, and manufacturing should treat this as a baseline assumption rather than a novel risk: ransomware actors are increasingly interested in physical impact, not just data encryption. The business case for that escalation — larger ransoms, faster payments — is obvious once you see it.


DevMan may be dormant. But the operational model they built, documented, and refined will outlast them.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)