AI Security AI安全 10h ago Updated 2h ago 更新于 2小时前 46

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts DevMan RaaS门户集中化载荷构建、受害者管理和佣金支付

DevMan RaaS, tracked as Funky Mantis, operates a centralized v3 portal formalizing affiliate workflows, victim management, and payout structures. The ransomware exhibits DragonForce lineage, utilizes ChaCha20-Poly1305 encryption with partial file encryption for large files, and targets Windows, ESXi, and Linux. Operators have developed specialized SCADA lockers designed to inflict physical hardware damage by pushing industrial control systems beyond thermal and operational limits. The operation DevMan RaaS(代号Funky Mantis)通过中心化门户平台实现载荷构建、受害者管理及佣金分发的全流程自动化,标志着勒索软件运营向企业化、结构化转型。 该组织开发了针对SCADA系统的专用加密器,旨在通过物理损坏(如过热)造成超越数据加密的工业破坏,显示攻击手段从单纯勒索向关键基础设施破坏升级。 内部治理高度集权,采用严格的角色分工(5个层级)和80/20分成模式,通过v3版本门户强化了对附属成员的控制力、工作流规范及多入侵管理。 尽管面临内部泄露威胁且近期活动停滞,DevMan仍保持高调宣传姿态,主要 targeting 美国科技、医疗及政府 sectors,并明确排除特定敏感区

65
Hot 热度
70
Quality 质量
60
Impact 影响力

Analysis 深度分析

TL;DR

  • DevMan RaaS, tracked as Funky Mantis, operates a centralized v3 portal formalizing affiliate workflows, victim management, and payout structures.
  • The ransomware exhibits DragonForce lineage, utilizes ChaCha20-Poly1305 encryption with partial file encryption for large files, and targets Windows, ESXi, and Linux.
  • Operators have developed specialized SCADA lockers designed to inflict physical hardware damage by pushing industrial control systems beyond thermal and operational limits.
  • The operation enforces strict governance with an 80-20 revenue split, role-based access controls, and specific targeting policies excluding CIS countries and minors.

Why It Matters

This case highlights the increasing professionalization of Ransomware-as-a-Service operations, where centralized platforms replace chaotic chat-based coordination to improve efficiency and affiliate retention. The development of SCADA-specific payloads that cause physical damage represents a significant escalation in threat severity, moving beyond data extortion to tangible industrial sabotage. Understanding these structural shifts and technical capabilities is crucial for defenders preparing for more sophisticated, organized, and physically impactful cyberattacks.

Technical Details

  • Portal Architecture: The v3 platform integrates payload building, finance tracking, victim chat, and team management, enforcing structured lifecycle states and deadline tracking to manage multiple intrusions simultaneously.
  • Encryption Methodology: The locker uses ChaCha20-Poly1305 for encryption; files under 3 MiB are fully encrypted, while larger files undergo partial encryption (1 MiB chunk every 51 MiB) to accelerate the process.
  • Malware Capabilities: Windows variants include privilege escalation checks, security control impairment, event log clearing, lateral movement, and multi-threaded encryption, with support for Windows, ESXi, and Linux environments.
  • SCADA Specialization: A distinct "SCADA locker" was developed to target industrial control systems, aiming to force hardware failure by exceeding processor, memory, and thermal limits.
  • Access Control: Five distinct operator roles were identified (LARVA-367 to LARVA-550), with affiliates requiring curator approval and facing removal if inactive for one month, reducing autonomous coordination.

Industry Insight

  • Organizations must enhance monitoring for SCADA and ICS environments, specifically looking for anomalies in thermal readings, processor loads, and hardware performance that may indicate malicious manipulation rather than standard operational stress.
  • Security teams should update detection rules to identify ChaCha20-Poly1305 encryption patterns and partial file encryption behaviors, which differ from traditional full-file ransomware approaches.
  • Incident response plans should account for the potential for physical infrastructure damage in critical sectors, requiring collaboration between IT security and OT (Operational Technology) engineering teams to mitigate hardware-level threats.

TL;DR

  • DevMan RaaS(代号Funky Mantis)通过中心化门户平台实现载荷构建、受害者管理及佣金分发的全流程自动化,标志着勒索软件运营向企业化、结构化转型。
  • 该组织开发了针对SCADA系统的专用加密器,旨在通过物理损坏(如过热)造成超越数据加密的工业破坏,显示攻击手段从单纯勒索向关键基础设施破坏升级。
  • 内部治理高度集权,采用严格的角色分工(5个层级)和80/20分成模式,通过v3版本门户强化了对附属成员的控制力、工作流规范及多入侵管理。
  • 尽管面临内部泄露威胁且近期活动停滞,DevMan仍保持高调宣传姿态,主要 targeting 美国科技、医疗及政府 sectors,并明确排除特定敏感区域以规避地缘政治风险。

为什么值得看

这篇文章揭示了勒索软件即服务(RaaS)模式正在经历深刻的“企业化”变革,通过技术平台将原本松散的犯罪网络转化为高度集中、流程标准化的非法业务实体。对于安全从业者而言,理解这种从聊天协调到结构化平台管理的演变,有助于预判未来勒索软件团伙在运营效率、攻击规模及对抗能力上的进一步提升。

技术解析

  • 中心化运营门户 (v3版本):DevMan推出了功能完备的Web平台,整合了载荷生成器(支持Windows, ESXi, Linux)、财务结算、受害者记录生命周期管理、团队邀请控制及截止日期追踪。这一架构取代了传统的基于聊天工具的松散协作,实现了多入侵事件的统一管理和工作流标准化。
  • 高级加密与持久化机制:Windows端载荷使用ChaCha20-Poly1305算法进行文件加密。针对大文件采用了混合策略:3 MiB以下文件完全加密,以上文件每51 MiB处理1 MiB块以实现部分加密,从而平衡加密速度与资源消耗。同时具备提权检测、安全软件禁用、进程终止、事件日志清除及自我删除等反取证功能。
  • SCADA专用恶意软件:DevMan承认开发了针对工业控制系统(ICS/SCADA)的特殊加密器。其核心逻辑不仅是数据锁定,而是通过强制处理器、内存和热力学参数超出运行极限,导致硬件过热直至物理损坏,这是一种极具破坏性的“物理层”攻击向量。
  • 访问经纪与部署整合:平台集成了访问权分销功能,管理员提供国家特定的“网络”接入点,并强制要求附属成员在2-3天内完成部署。这种将初始访问销售与勒索软件投放紧密结合的模式,提高了攻击链条的转化率和执行效率。

行业启示

  • RaaS平台的“SaaS化”趋势:勒索软件团伙正迅速采用类似合法SaaS产品的管理工具,通过API、仪表盘和自动化工作流提升运营效率。防御方需关注此类平台的技术特征,将其视为一种新型的基础设施威胁,而不仅仅是单个恶意软件样本。
  • 关键基础设施面临物理级威胁:DevMan对SCADA系统的针对性开发表明,勒索软件攻击的边界已从数字资产扩展到物理世界。能源、制造等关键行业必须重新评估其OT(运营技术)安全策略,不仅防范数据泄露,更要防范可能导致设备损坏或生产中断的物理攻击。
  • 内部治理与合规风险的双刃剑:虽然DevMan禁止攻击儿童医疗机构和泄露未成年人数据,但这更多是出于品牌声誉和避免过度执法的关注,而非真正的道德约束。这种“选择性合规”策略可能使其在某些司法管辖区获得相对宽松的生存空间,同时也提醒企业,即使面对有“底线”的勒索团伙,也不能放松基础的安全防护。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全