The DevMan ransomware-as-a-service (RaaS) operation has developed a comprehensive web platform that enables affiliates to construct payloads, manage financial transactions, and oversee victim interactions. This centralized system integrates access brokerage with ransomware deployment, offering country-specific networks and imposing strict completion timelines of two to three days.
Initially emerging in April 2025 as an affiliate for groups like Qilin, DragonForce, Apos, and RansomHub, DevMan transitioned to its own RaaS model. The ransomware shares significant code similarities with DragonForce, indicating a shared lineage. In a 2025 interview, DevMan disclosed collaborations with Conti and detailed the creation of a specialized SCADA locker designed to inflict physical damage on industrial control systems by pushing them beyond operational limits.
Despite a setback in June 2025, when a whistleblower known as GangExposed revealed operator identities, leading to affiliate departures, DevMan has continued to evolve. The third version of their affiliate portal, released in January 2026, introduced features such as structured victim records, lifecycle states, team creation, and deadline tracking, aiming to formalize affiliate workflows and enhance operational efficiency.
To date, DevMan has claimed 184 victims, with nearly 50 located in the United States, targeting sectors including technology, healthcare, financial services, professional services, and government. The group’s ability to adapt and enhance its platform underscores the persistent and evolving nature of cyber threats, highlighting the need for robust cybersecurity measures and continuous vigilance.