What Happened
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. Swiss cybersecurity company PRODAFT is tracking the centrally administered RaaS operation under the name Funky Mantis. "The portal combined build generation, finance,
Why It Matters
The article reports that DevMan (tracked as Funky Mantis) operates a centralized ransomware-as-a-service portal that automates payload generation, victim management, affiliate coordination, and payout handling for 184 claimed victims, with features spanning build generation, finance, victim chat, support, team management, and an 80/20 revenue split.[1][5][6] These functions mirror legitimate SaaS and orchestration platforms, and similar automation or agent-like tooling could be repurposed or augmented by AI to scale targeting, negotiation, and operational decision-making.[3][6][8] From a RealGround perspective, this illustrates a mature criminal "service" model that can easily integrate AI-driven recon, targeting, and negotiation, increasing speed and impact of ransomware campaigns. Organizations should harden against automated, service-based extortion ecosystems by continuously red-teaming their AI-assisted defenses and incident workflows, and by assessing AI-related supply-chain exposure so that internal automation, orchestration tools, and AI agents cannot be abused or mirrored by adversaries to run DevMan-style operations.
RealGround Analysis
This signal maps to malicious AI use. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.
Recommended Actions
- Restrict AI agent tool permissions and production write paths.
- Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
- Add human approval workflows for high-impact or state-changing actions.
- Run prompt injection and indirect prompt injection tests against affected workflows.
- Document the owner, control gap, and remediation deadline for this risk class.
Source
https://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.html
