Operators behind the DevMan ransomware-as-a-service offering have built a centralized web portal that hands affiliates a near-complete toolkit for running attacks, according to research highlighted by The Hacker News. While RaaS models are not new, this platform represents a significant shift toward a fully managed "franchise" service that automates the entire attack lifecycle. The portal lets participants generate custom payloads, track victims, and handle financial payouts from a single interface, effectively packaging criminal operations into a streamlined product.
Swiss threat-intelligence firm PRODAFT is monitoring the activity under the internal designation Funky Mantis. Researchers describe a purpose-built portal that consolidates the core stages of a ransomware campaign—payload construction, victim oversight, and revenue distribution—into one administered service. Affiliates no longer need to assemble disparate tools or manage complex backend logistics themselves; the operators supply the infrastructure and take a cut of the proceeds.
This model marks a clear step toward the industrialization of ransomware. By abstracting away technical complexity, the DevMan portal lowers the skill threshold required to launch extortion campaigns. What once demanded coding ability, infrastructure knowledge, and operational security experience can now be approached more like subscribing to a criminal software-as-a-service product. The result is an expanded pool of potential attackers and faster scaling for the operators who control the core platform.
Security observers note that the same centralization that makes the scheme efficient also introduces a strategic weakness. Because payload builds, victim data, and payment flows all route through one managed system, a successful disruption—whether by law enforcement takedown or technical intervention—could simultaneously impair every affiliate relying on it. For defenders, this highlights a crucial tactical pivot: beyond traditional malware signature detection, monitoring the administrative layer itself—for patterns in portal traffic, authentication flows, or API requests linked to known RaaS infrastructure—can provide earlier warning of campaigns. This centralized model, while potent for attackers, creates a single point of failure that, if disrupted, could cripple the entire affiliate network, underscoring the need for defense strategies that target these management platforms directly.
據 The Hacker News 報導的研究,DevMan 勒索軟件即服務背後的營運者建立了一個集中化網絡門戶,為附屬機構提供近乎完整的工具包以執行攻擊。雖然 RaaS 模式並不新穎,但此平台代表朝向完全託管的「特許經營」服務的顯著轉變,自動化了整個攻擊週期。該門戶讓參與者能在單一介面中生成自訂有效載荷、追蹤受害者並處理財務支付,將犯罪操作實質上包裝成精簡化的產品。
瑞士威脅情報公司 PRODAFT 正以內部代號「Funky Mantis」監測此活動。研究人員描述一個專門建造的門戶,將勒索軟件活動的核心階段——有效載荷構建、受害者監察及收益分配——整合到一個由管理員控制的服務中。附屬機構無需自行組裝零散工具或管理複雜的後台後勤;營運者提供基礎設施並從收益中抽成。
此模式標誌著勒索軟件朝工業化發展的明確一步。透過抽象化技術複雜性,DevMan 門戶降低了發動勒索攻擊所需的技能門檻。以往需要編程能力、基礎設施知識及操作安全經驗的工作,現在可以更像訂閱犯罪軟件即服務產品般進行。結果是潛在攻擊者池擴大,而控制核心平台的營運者得以更快擴展規模。
安全觀察人士指出,使此計劃高效的集中化特性,同時引入了戰略弱點。由於有效載荷構建、受害者資料及支付流皆透過同一託管系統,一次成功的打擊——無論是執法部門取締還是技術干預——可能同時損害所有依賴此系統的附屬機構。對防禦者而言,這突顯了一個關鍵戰術轉變:除了傳統的惡意軟件特徵檢測,監測管理層本身——如門戶流量模式、認證流程或與已知 RaaS 基礎設施相關的 API 請求——可提供更早期的攻擊預警。這種集中化模式雖對攻擊者強效,但創造了單點故障,若遭破壞,可能癱瘓整個附屬網絡,凸顯了直接針對這些管理平台制定防禦策略的必要性。
