HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Ransomware‑as‑a‑Service ‘DevMan’ Centralizes Payload Builds, Affiliate Payouts, and Victim Management

The DevMan RaaS platform lets affiliates generate ransomware payloads, track victims, and manage earnings from a single web portal. This operational model highlights the need for SOC 2‑aligned access controls and continuous security‑awareness training to detect and block malicious code creation.

LiveThreat™ Intelligence · 📅 July 25, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
thehackernews.com

Ransomware‑as‑a‑Service “DevMan” Centralizes Payload Builds, Affiliate Payouts, and Victim Management

What Happened — Operators of the DevMan ransomware‑as‑a‑service (RaaS) scheme are running a dedicated web portal that lets affiliates generate ransomware payloads, track victim data, and manage their earnings. The platform, tracked by Swiss firm PRODAFT under the name “Funky Mantis,” consolidates build generation, finance, and victim‑management functions in a single, subscription‑based service.

Why It Matters for Compliance & Audit Readiness

  • SOC 2 CC6.1 (Logical Access) and CC7.1 (System Operations) require documented controls over who can create, modify, or deploy code—exactly the capabilities the DevMan portal automates for malicious actors.
  • Continuous‑control monitoring and audit‑ready evidence (e.g., privileged‑access logs, change‑management records) are essential to demonstrate that your organization can detect and block unauthorized payload generation.
  • Security‑awareness training that covers ransomware delivery vectors (phishing, malicious attachments, compromised supply‑chain tools) directly mitigates the primary infection path used by RaaS affiliates.

Who Is Affected — Any sector that relies on Windows‑based endpoints, file‑sharing services, or third‑party software supply chains (healthcare, finance, technology, manufacturing, etc.).

Recommended Actions

  • Map your incident‑response and logical‑access controls to SOC 2 criteria; ensure you can produce real‑time logs of code‑signing and executable creation.
  • Deploy or refresh security‑awareness training that includes ransomware‑specific phishing simulations and payload‑recognition drills.
  • Implement continuous monitoring of outbound traffic for anomalous payload‑generation patterns and enforce least‑privilege for any build‑automation tools.

Source: The Hacker News

Technical Notes

  • Attack vector: RaaS portal (web‑based SaaS) used by affiliates to craft and deliver ransomware payloads.
  • Key capabilities exposed: automated payload generation, victim‑profile storage, affiliate‑payment tracking.
  • No public CVE – the threat is operational rather than a software flaw.

Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →