Ethical Hacking News
DevMan RaaS Portal Exposed: A Comprehensive Analysis of the Centralized Payload Build, Victim Management, and Affiliate Payouts Mechanism
The DevMan ransomware-as-a-service (RaaS) scheme has a centralized web platform offering affiliates various functions, including building payloads, managing victims, and receiving payouts. The operation emerged in April 2025 as an affiliate for other ransomware groups but later shifted to its own RaaS operation. DevMan acknowledged working with Conti and developed a specialized SCADA locker designed to target industrial control systems. The group faced challenges after a public doxxing of operator identities, leading to the abandonment of some affiliates. The third version (v3) of the platform offers enhanced features, including support for structured victim records and per-victim build options. DevMan's governance model reserves administrator power to enforce operational tempo and protect revenue, reducing affiliate autonomy. The illicit proceeds follow an 80-20% split, allowing affiliates to earn a substantial chunk of the profits. Organizations are advised to implement security measures, such as phishing-resistant MFA and rotating credentials, to counter DevMan's activities.
The cybersecurity landscape has witnessed the emergence of a sophisticated ransomware-as-a-service (RaaS) scheme known as DevMan. This operation has garnered significant attention due to its centralized web platform, which offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. In this article, we will delve into the intricacies of DevMan's RaaS portal, exploring its evolution, key features, and implications for organizations.
The DevMan RaaS operation was first tracked by Swiss cybersecurity company PRODAFT in July 2026. The company revealed that the operators of the scheme maintained a dedicated web platform, which integrated various functions, including build generation, finance, victim chat, support, victim records, teams, and payout functions. This centralized platform allowed affiliates to manage their operations, including building payloads, managing victims, and receiving payouts.
The DevMan RaaS operation has its roots in April 2025, when it emerged as an affiliate for Qilin, DragonForce, Apos, and RansomHub. However, the group soon shifted to its own RaaS operation, showcasing its adaptability and ability to evolve in response to changing circumstances. According to Vectra AI, the locker's DNA is "unmistakably DragonForce," highlighting the group's connections to other ransomware operations.
In an interview with security researcher Jon DiMaggio published in October 2025, DevMan acknowledged working with Conti and claimed to have developed a specialized SCADA locker designed to target an unnamed gas company. The threat actor stated that the malware would "push industrial control systems beyond their operating parameters, processors, memory, and thermal limits, forcing systems to ramp up and run hot until hardware failed."
DevMan's operations have faced several challenges, including a public doxxing of operator identities by a mysterious whistleblower known as GangExposed in June 2025. This incident led to the abandonment of some affiliates and raised concerns about the group's ability to maintain its operations.
Despite these challenges, DevMan has continued to evolve and improve its platform. The third version (v3) of the platform, released in January 2026, comes with enhanced features, including support for structured victim records, life cycle states, team creation, invitation controls, per-victim build options, deadline tracking, revenue fields, and shared operational access.
PRODAFT has identified five distinct roles within DevMan's operations:
1. LARVA-367: Administrator/owner and central coordinator
2. LARVA-546: Access coordinator named as an alternative point of contact for network access
3. LARVA-547: Senior operator
4. LARVA-548: Senior operator or coordinator
5. LARVA-550: Affiliate/operator who was credited for an installation in an actor-controlled group message
The governance model employed by DevMan reserves the right to take over a conversation if an affiliate behaves inappropriately or fails to adhere to a commitment, reducing affiliate autonomy while giving administrators the power to enforce operational tempo and protect revenue.
The illicit proceeds obtained after successful extortion follow an 80-20% split, allowing affiliates to earn a substantial chunk of the profits. The v3 platform rules state that ransom funds are sent to two wallets, one for the affiliate and one linked to the RaaS program.
DevMan's stated targeting policy allows affiliates to strike entities outside the CIS countries and Serbia, excluding CIS consulates and CIS-linked companies. However, it also forbids affiliates from attacking child-related healthcare businesses and intentional leaks of personal data belonging to people under the age of 18.
The latest version of the platform allows affiliates to create a locker for Windows, ESXi, or Linux. An analysis of the Windows version has identified functions related to privilege checking, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion.
Organizations are advised to prohibit service and backup accounts from interactive VPN login unless a documented operational requirement exists. Remote access and privileged administration should use phishing-resistant MFA. Teams should rotate credentials exposed to VPN appliances, LDAP integrations, scripts, and backup tooling, with priority given to secrets that can grant local or domain administrative access.
In conclusion, the DevMan RaaS operation represents a significant threat to organizations worldwide. Its centralized web platform offers affiliates a range of features, including build generation, finance, victim chat, support, victim records, teams, and payout functions. Understanding the intricacies of this operation is crucial for developing effective strategies to counter its activities.
DevMan RaaS Portal Exposed: A Comprehensive Analysis of the Centralized Payload Build, Victim Management, and Affiliate Payouts Mechanism
Related Information:
https://www.ethicalhackingnews.com/articles/DevMan-RaaS-Portal-Exposed-A-Comprehensive-Analysis-of-the-Centralized-Payload-Build-Victim-Management-and-Affiliate-Payouts-Mechanism-ehn.shtml
https://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.html
Published: Sat Jul 25 08:07:15 2026 by llama3.2 3B Q4_K_M