DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
DevMan RaaS, tracked as Funky Mantis, operates a centralized v3 portal formalizing affiliate workflows, victim management, and payout structures. The ransomware exhibits DragonForce lineage, utilizes ChaCha20-Poly1305 encryption with partial file encryption for large files, and targets Windows, ESXi, and Linux. Operators have developed specialized SCADA lockers designed to inflict physical hardware damage by pushing industrial control systems beyond thermal and operational limits. The operation
Analysis
TL;DR
- DevMan RaaS, tracked as Funky Mantis, operates a centralized v3 portal formalizing affiliate workflows, victim management, and payout structures.
- The ransomware exhibits DragonForce lineage, utilizes ChaCha20-Poly1305 encryption with partial file encryption for large files, and targets Windows, ESXi, and Linux.
- Operators have developed specialized SCADA lockers designed to inflict physical hardware damage by pushing industrial control systems beyond thermal and operational limits.
- The operation enforces strict governance with an 80-20 revenue split, role-based access controls, and specific targeting policies excluding CIS countries and minors.
Why It Matters
This case highlights the increasing professionalization of Ransomware-as-a-Service operations, where centralized platforms replace chaotic chat-based coordination to improve efficiency and affiliate retention. The development of SCADA-specific payloads that cause physical damage represents a significant escalation in threat severity, moving beyond data extortion to tangible industrial sabotage. Understanding these structural shifts and technical capabilities is crucial for defenders preparing for more sophisticated, organized, and physically impactful cyberattacks.
Technical Details
- Portal Architecture: The v3 platform integrates payload building, finance tracking, victim chat, and team management, enforcing structured lifecycle states and deadline tracking to manage multiple intrusions simultaneously.
- Encryption Methodology: The locker uses ChaCha20-Poly1305 for encryption; files under 3 MiB are fully encrypted, while larger files undergo partial encryption (1 MiB chunk every 51 MiB) to accelerate the process.
- Malware Capabilities: Windows variants include privilege escalation checks, security control impairment, event log clearing, lateral movement, and multi-threaded encryption, with support for Windows, ESXi, and Linux environments.
- SCADA Specialization: A distinct "SCADA locker" was developed to target industrial control systems, aiming to force hardware failure by exceeding processor, memory, and thermal limits.
- Access Control: Five distinct operator roles were identified (LARVA-367 to LARVA-550), with affiliates requiring curator approval and facing removal if inactive for one month, reducing autonomous coordination.
Industry Insight
- Organizations must enhance monitoring for SCADA and ICS environments, specifically looking for anomalies in thermal readings, processor loads, and hardware performance that may indicate malicious manipulation rather than standard operational stress.
- Security teams should update detection rules to identify ChaCha20-Poly1305 encryption patterns and partial file encryption behaviors, which differ from traditional full-file ransomware approaches.
- Incident response plans should account for the potential for physical infrastructure damage in critical sectors, requiring collaboration between IT security and OT (Operational Technology) engineering teams to mitigate hardware-level threats.
Disclaimer: The above content is generated by AI and is for reference only.