Ransomware crews used to run on Telegram threads and trust. Now they’re shipping v3 platforms with role-based access control, curator approval workflows, and 80/20 revenue splits — and one of them just added a specialized SCADA locker designed to physically destroy hardware. The professionalization of extortion isn’t coming. It’s already in production.
How DevMan Turned Ransomware Into a SaaS Product
According to Swiss cybersecurity firm PRODAFT, which tracks the operation under the name Funky Mantis, DevMan operators are running a centralized web portal that bundles payload builders, finance dashboards, victim chat, help desk tickets, team management, and payout functions into a single console. The third version of the platform, released in January 2026, adds structured victim records, life cycle states, invitation controls, per-victim build options, and deadline tracking. PRODAFT calls it “an effort to formalize affiliate workflows and manage multiple intrusions through a common platform rather than relying only on chat-based coordination.”
The platform changes the economics of who can operate ransomware. When it handles builder generation, victim triage, and split payouts across two wallets automatically, the technical bar for an affiliate drops to “can get initial access and click through a wizard.” That’s a step-function increase in the number of viable operators, and every one of them is chasing the 80% cut the RaaS program advertises.
If you run a mid-market IT team, this means the attacker landing in your environment next quarter probably didn’t write the locker, didn’t design the negotiation flow, and doesn’t need to. They rented the whole stack. Expect the volume of competent-enough ransomware attempts to keep climbing even as individual actor skill regresses toward the mean.
Why the SCADA Locker Should Terrify Critical Infrastructure Teams
In an October 2025 interview with security researcher Jon DiMaggio, DevMan claimed to have built a “specialized SCADA locker” targeting an unnamed gas company, designed to push industrial control systems “beyond their operating parameters, processors, memory, and thermal limits, forcing systems to ramp up and run hot until hardware failed.” DevMan’s targeting policy, per PRODAFT, explicitly encourages attacks against critical infrastructure and instructs affiliates to request a separate encryptor for SCADA systems.
Ransomware has historically been about denial-of-availability through encryption — bad, but reversible with backups. A payload designed to cause progressive physical damage turns a data recovery incident into a capital equipment replacement incident. The recovery time objective isn’t “restore from backup,” it’s “procure a new turbine.” For any operator running OT alongside IT — utilities, manufacturers, supply chain and logistics platforms, EV charging networks — the blast radius calculation just changed.
Imagine a regional water utility with flat network segmentation between corporate IT and the SCADA VLAN. An affiliate buys initial access from a broker, deploys the DevMan builder against Windows and ESXi hosts, then requests the SCADA-specific encryptor to hit the historian and PLC gateways. The cleanup isn’t 72 hours of restoration — it’s months of vendor engagement and possible regulatory intervention.
My prediction: within the next 12 months we’ll see at least one publicly attributed OT ransomware incident that names physical equipment damage, not just encryption, as the primary loss vector.
The Governance Model Nobody Expected From Criminals
PRODAFT identified five distinct roles inside DevMan — LARVA-367 as administrator, LARVA-546 as access coordinator, senior operators LARVA-547 and LARVA-548, and affiliate LARVA-550 — with formal onboarding rules that would look familiar to any HR team. Affiliates get added to the corporate chat only after producing a first victim, get assigned an “experienced curator,” and can be removed after one month without a new victim. Team formation and disclosure of program affiliation require curator approval, and administrators reserve the right to take over conversations if an affiliate misbehaves.
The 80/20 revenue split is enforced at the wallet level — ransom funds route to two separate wallets automatically. Two-to-three-day completion windows are imposed on affiliates using program-supplied access. The targeting policy carves out CIS countries, Serbia, CIS consulates, and child-related healthcare businesses, while lifting a previous restriction on Saudi Arabia.
What this really shows: DevMan is optimizing for revenue predictability the same way any SaaS company does. Enforced SLAs, curator-driven quality control, formalized offboarding. Defenders who still model ransomware operators as chaotic lone-wolf hackers are calibrating against a threat that doesn’t exist anymore.
The Huntress Insider Allegation Nobody Wants to Talk About
The timing of the PRODAFT report collides with an uncomfortable disclosure. Former Huntress employee Ben Folland publicly accused a current Huntress analyst of forwarding FBI communications about DevMan — including screenshots with agent names — directly to the threat actor in December 2025. Huntress CEO Kyle Hanslovan confirmed the exchange in a blog post, describing it as “poor judgment” but not illegal, and said the company “implemented more robust policies for our researchers” as a result.
Folland’s counter is direct: “If someone inside a bank warns a fraudster that police are investigating them, nobody would describe that as merely ‘poor judgment.’ They would call it what it is — an insider.”
Why this matters for your vendor risk program: threat research teams sit on some of the most sensitive data flows in the industry — law enforcement liaison, victim identities, IOC pre-disclosure. If you’re a CISO evaluating managed detection and response vendors, the question of what policies govern researcher-to-actor communication is no longer academic. Expect MDR RFPs to start requiring specific controls around threat actor engagement logging, chain-of-custody for law enforcement communications, and mandatory dual-control on any outbound message to a known adversary.
The Locker Itself: Boring, Effective, ChaCha20-Poly1305
The Windows locker PRODAFT analyzed handles privilege checks, security control impairment, process and service termination, recovery inhibition, event log clearing, discovery, lateral movement, multi-threaded encryption, and optional self-deletion — the standard modern ransomware feature checklist. Files up to 3 MiB are fully encrypted with ChaCha20-Poly1305; anything larger gets partial encryption of a 1 MiB chunk every 51 MiB. Builders for Windows, ESXi, and Linux are all available in the portal.
PRODAFT’s operational guidance is worth quoting directly: “Organizations should prohibit service and backup accounts from interactive VPN login unless a documented operational requirement exists. Remote access and privileged administration should use phishing-resistant MFA. Teams should rotate credentials exposed to VPN appliances, LDAP integrations, scripts, and backup tooling, with priority given to secrets that can grant local or domain administrative access.”
None of that is novel advice. It’s the same guidance that would have blocked most of the 184 victims DevMan has claimed on Ransomware.Live, nearly 50 of whom are in the U.S., with technology, healthcare, financial services, professional services, and government sectors bearing the brunt. The controls exist. The gap is enforcement.
FAQ
Q: What is DevMan ransomware and how is it different from other RaaS operations? A: DevMan is a ransomware-as-a-service program tracked by PRODAFT under the name Funky Mantis. It emerged in April 2025 as an affiliate for Qilin, DragonForce, Apos, and RansomHub before launching its own operation. What separates it is the v3 affiliate portal — a centralized platform combining payload builds, victim management, finance, and payouts, with formal role hierarchy and curator-driven onboarding.
Q: Is the SCADA locker DevMan claims to have built actually deployed? A: DevMan told researcher Jon DiMaggio the SCADA locker was used against an unnamed gas company, but there has been no independent public confirmation of physical damage. PRODAFT confirms the targeting policy instructs affiliates to request a separate SCADA encryptor, which corroborates that development is underway or complete.
Q: What should defenders prioritize based on this reporting? A: Per PRODAFT, prohibit service and backup accounts from interactive VPN login, enforce phishing-resistant MFA on remote access and privileged administration, and rotate credentials exposed to VPN appliances, LDAP integrations, scripts, and backup tooling. Prioritize secrets that grant local or domain admin.
Key Takeaways
- Ransomware operations are converging on SaaS-style platforms with role-based governance — model your threat actors accordingly, not as opportunistic individuals.
- OT and critical infrastructure teams should assume the next ransomware wave includes payloads designed to cause physical damage, not just encryption; segment SCADA aggressively and treat historian access as tier-zero.
- Vendor risk reviews for MDR and threat intelligence providers should now include explicit questions about researcher-to-actor engagement policies and law enforcement liaison controls.
- Expect a 12-month window in which OT-aware ransomware becomes a distinct product category, with pricing and affiliate specialization to match.
- Basic hygiene — MFA on remote access, service account restrictions, credential rotation — still blocks most of what these portals ship, but only if it’s actually enforced across VPN, LDAP, and backup tooling.