🟠 High  |  Source: The Hacker News


A ransomware-as-a-service (RaaS) operation called DevMan, tracked by PRODAFT under the name Funky Mantis, is running a centralised web portal that allows criminal affiliates to build ransomware payloads, manage victims, and handle financial payouts. This professionalised infrastructure lowers the technical barrier for would-be ransomware attackers, effectively scaling the threat. The existence of a polished affiliate portal signals an organised, ongoing operation with the potential to target organisations across multiple sectors.

Security Architect’s Take: Review your ransomware defence posture now: ensure immutable, offline backups are in place and tested, enforce least-privilege access across cloud workloads to limit lateral movement, and validate that endpoint detection and response (EDR) tooling is deployed consistently — including on cloud-hosted virtual machines — to catch payload execution early.

Original advisory: DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts