How a New RaaS Portal Streamlines Ransomware Attacks for Affiliates
Robert Moore ยท
Listen to this article~4 min
A new RaaS portal from DevMan operators centralizes payload builds, victim management, and affiliate payouts, making ransomware attacks easier for criminals. PRODAFT tracks the operation under Funky Mantis.
The operators behind the DevMan ransomware-as-a-service (RaaS) scheme have built a dedicated web platform that gives affiliates everything they need to launch attacks, manage victims, and track payouts. It's a centralized hub that makes the whole process smoother for cybercriminals.
Swiss cybersecurity firm PRODAFT is tracking this operation under the name Funky Mantis. Their research shows the portal handles build generation, financial oversight, and victim management all in one place.
### What Makes This Portal Different?
Most RaaS operations rely on scattered tools and manual coordination. But DevMan's approach is different. It brings everything under one roof. Affiliates can:
- Build custom ransomware payloads tailored to specific targets
- Monitor infection progress and victim status in real time
- Track earnings and affiliate payouts automatically
- Manage communications with victims for ransom demands
This level of organization makes it easier for less technical criminals to get involved. It lowers the barrier to entry for launching sophisticated attacks.
### The Financial Side of the Operation
Payouts are handled through the portal itself. Affiliates get a clear dashboard showing their earnings in USD. The system calculates splits based on pre-agreed terms, so everyone knows exactly what they're owed.
PRODAFT estimates that successful attacks can net affiliates anywhere from $10,000 to $500,000 per victim, depending on the size and sector of the target. The portal tracks these payments automatically.
### Why This Matters for Security Teams
For defenders, this kind of centralized platform is both a threat and an opportunity. It means attacks can be launched faster and with less preparation. But it also creates a single point of failure. If researchers can find a way to disrupt the portal, they could cripple the entire operation.
Security teams need to watch for signs of DevMan activity. Indicators include specific file hashes, command-and-control IP addresses, and ransom note templates that match known versions of the ransomware.
### How to Protect Your Organization
Staying safe from RaaS attacks like DevMan requires a proactive approach. Here are some practical steps:
- Keep all software updated to patch known vulnerabilities
- Train employees to spot phishing emails that often deliver ransomware
- Use endpoint detection tools that can spot unusual behavior
- Back up critical data regularly and store backups offline
- Implement strict access controls to limit lateral movement
No single solution will stop every attack. But layering these defenses makes it much harder for attackers to succeed.
### The Bigger Picture
RaaS platforms are evolving fast. DevMan's portal is just one example of how cybercriminals are professionalizing their operations. They're building tools that rival legitimate software in terms of usability and features.
For businesses, this means the threat landscape is becoming more complex. Attacks that once required deep technical knowledge can now be carried out by anyone with a few hundred dollars and an internet connection.
Staying informed about these developments is critical. Following research from firms like PRODAFT helps security teams understand what they're up against and how to prepare.
In the end, the best defense is a combination of technology, training, and vigilance. RaaS platforms may be getting more sophisticated, but so are the tools and strategies available to protect against them.
A deeper breakdown of GoLogin Review 2026 โ Fast, affordable anti-detect browser with cloud profiles - real examples, numbers, and what actually works.
A deeper breakdown of Undetectable.io Review 2026 โ Unlimited local profiles with solid fingerprint masking - real examples, numbers, and what actually works.