PRODAFT Documents "DevMan" Ransomware-as-a-Service Portal Operated by "Funky Mantis"
Another named RaaS operator profile from PRODAFT — defender-team pattern-tracking this weekend.
Key Takeaways
|
PRODAFT adds another named RaaS operator to the public record — the defender-relevant detail is consolidation, not a payload to reverse.
YVERDON-LES-BAINS, SWITZERLAND — Swiss cybersecurity company PRODAFT on July 25, 2026 documented a ransomware-as-a-service (RaaS) portal it calls "DevMan," operated — per its reporting — by an actor the firm tracks as "Funky Mantis." The portal reportedly pulls payload build generation, finance and payout management, and victim oversight together into a single centralized web interface, rather than leaving those functions spread across chat channels and improvised tooling.
The framing is what makes the disclosure useful to defenders rather than a technical curiosity. As reported by The Hacker News, PRODAFT's account reads less as a new exploit and more as a business-operations profile of a ransomware program: how the operation is organized, what its console does, and how affiliate work is coordinated. This piece summarizes what the disclosure documents and what remains unconfirmed, in defender terms, and does not reconstruct how any payload is built.
| At a Glance | |
|---|---|
| Field | Details |
| What | Research disclosure of "DevMan," a centralized RaaS operator portal |
| Who documented it | PRODAFT, a Switzerland-based cyber threat intelligence firm |
| Operator | Tracked by PRODAFT as "Funky Mantis," per reporting |
| Reported portal functions | Payload build generation, finance/payout management, victim oversight — in one interface |
| Disclosure date | July 25, 2026 |
| Named victims | None established in the reporting reviewed — open question |
| Affiliate count | Not established — open question |
| Related coverage | CyberSignal RaaS operator-profile and ransomware coverage |
What PRODAFT Documented
According to reporting from The Hacker News, PRODAFT profiled DevMan as a centrally administered RaaS operation whose operators maintain a dedicated web platform for affiliates. The central claim, in defender terms, is one of consolidation: build generation, finance, victim records, support, team management, and payout functions are reportedly reachable from a single operator-run console. PRODAFT tracks the operation under the name Funky Mantis.
The CyberSignal is deliberately not reproducing how any payload is generated. The defender-relevant facts are the shape of the finding — a named RaaS program run as a consolidated, self-service platform — the firm that documented it, and the framing. This is a research disclosure of an operation's structure, not an advisory tied to a specific breach; in the reporting reviewed, PRODAFT named no victim organization and put no figure on the operation's total affiliate roster.
Reporting also describes DevMan as having evolved over time from affiliate work into its own RaaS program, with the portal reaching later, more structured versions. The CyberSignal notes that evolution as reported context rather than a verified timeline, and does not treat it as establishing that DevMan overlaps with any specific, publicly tracked operator — a point the disclosure does not settle.
The Centralized-Portal Framing in Defender Terms
The detail worth translating for a defender team is the consolidation itself. A ransomware program that runs build generation, victim management, and payout accounting from one interface is behaving less like a loose crew and more like a software-as-a-service business — with onboarding, workflows, and deadlines. That professionalization does not change what defenders block, but it does change what they should expect: faster affiliate ramp-up, more consistent tradecraft across intrusions, and a lower barrier to entry for the people carrying them out.
This is a RaaS-ecosystem awareness point, not a to-do list generated from the portal's internals. The useful posture is pattern-tracking: understanding that the operator layer is maturing, that affiliate economics are what drive intrusion volume, and that the controls which matter — identity hardening, segmentation, tested and isolated backups, and behavior-based detection — are the same regardless of which console an affiliate logged into. The console is the operator's convenience; the intrusion is still where defenders meet the threat.
Continuation Context: A Growing Catalog of RaaS Operator Profiles
DevMan does not arrive in isolation. It is the latest entry in a steady run of RaaS operator profiles that vendors have published in 2026, and reading it alongside the others is where its value compounds. It rhymes with Unit 42's profile of "The Gentlemen" ransomware and the affiliate model driving its growth, where the business framing — how affiliate incentives scale a program — was the load-bearing insight rather than any single indicator. That operation has also been tracked across worm-like spread and a victim count well into the hundreds, underscoring how quickly a well-organized affiliate program can scale.
The research-disclosure discipline is the same one The CyberSignal applied to Sysdig's work on JadePuffer and its purpose-built AI-model ransomware and to researcher findings on INC ransomware activity across 830-plus victims: take the profile seriously as early awareness of how an operation is organized, and resist over-reading a vendor write-up as an imminent incident against any one organization. DevMan belongs in that catalog — a named operator whose structure is now on the public record, worth understanding before an affiliate using it turns up in an environment.
Defender Takeaways
Because this is an operator profile rather than a victim-specific advisory, its most productive use is a posture check against the general shape of RaaS intrusions. The consolidation PRODAFT describes reinforces, rather than rewrites, the defensive priorities: ransomware readiness rests on identity and access hardening, network segmentation that limits blast radius, monitoring for anomalous access, and backups that are tested, isolated, and restorable. None of those depend on knowing the internals of any particular portal.
The pattern-tracking takeaway is to treat the maturing operator layer as a planning input. A more professionalized RaaS front end tends to mean more affiliates and more uniform behavior downstream, which is an argument for detection built on intrusion behaviors — credential abuse, lateral movement, staging, and mass file changes — that outlast any single operator or indicator. Awareness of who is running the platforms is useful; the durable defenses sit at the intrusion, not the console.
Open Questions
Several specifics are unresolved at publication, and The CyberSignal is not filling them in. It is not established in the reporting reviewed how many affiliates DevMan has, which organizations, if any, it has victimized, whether DevMan overlaps with any publicly tracked RaaS operator, or whether law enforcement has been notified. The disclosure is framed as a profile of an operation's structure, and those gaps bound what can responsibly be drawn from it.
As with any single-vendor write-up, the picture will sharpen if other researchers corroborate the profile, if victims or law-enforcement action surface, or if PRODAFT publishes further detail. Until then, the responsible reading is the one above: a named RaaS operator documented at a reputable firm, logged for awareness and pattern-tracking, not escalated into an incident that has not been reported.
The CyberSignal Analysis
The reported facts above come from PRODAFT's disclosure and its reporting; what follows is The CyberSignal's editorial reading. None of the judgments below are new reported facts, and none reconstruct how the operation builds or deploys anything.
Signal 01 — The Story Is Professionalization, Not a New Payload
The instinct with any ransomware disclosure is to ask what to reverse and what to block. Our reading is that DevMan rewards a different question: what does it mean that the operator layer keeps getting more organized? A single console spanning build, billing, and victim management is the tell of a program run like a business, and business maturity — not a novel encryptor — is the through-line worth tracking here.
The consequence for defenders is to watch the operator ecosystem as a trend, not just to catalog payloads. Programs that lower the barrier for affiliates tend to produce more intrusions with more consistent tradecraft, which is a planning signal about volume and uniformity that no single indicator captures.
Signal 02 — Read It as Awareness, Not an Incident
Our assessment is that the correct posture is calibrated attention. This is a vendor profile of an operation's structure, with no named victim and no reported enforcement action — not an advisory about an active breach in anyone's environment. Treating it as an emergency would misallocate effort; ignoring it because no incident is attached would waste a useful piece of ecosystem intelligence.
The useful middle is to log DevMan and Funky Mantis as known entities and let the pattern accumulate. Defenders who track the operator catalog will recognize the next profile — or the affiliate behind the next intrusion — faster than those meeting each name cold.
Signal 03 — The Defenses Sit at the Intrusion, Not the Console
The detail we find most durable is that none of the portal's internals change what actually stops a RaaS affiliate. Our view is that the console is the operator's convenience and the intrusion is the defender's ground: identity hardening, segmentation, monitoring, and tested backups are where a ransomware event is won or lost, whichever platform generated the payload.
That is why the guidance above is framed around behavior and recovery rather than portal-specific indicators. The operator layer will keep professionalizing; the organizations that invest in intrusion-behavior detection and restorable backups will absorb the next well-run RaaS program with the least disruption.