DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // DEVMAN-FUNKY-MANTISFIRST SEEN: APR 2025

DEVMAN

ALSO KNOWN AS: Funky Mantis (PRODAFT), LARVA-367 (core operator alias)
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Unknown — Eastern European / Russian-speaking cybercrime ecosystem
ATTRIBUTION:ORGANIZED CRIME
STATUS:DORMANT
FIRST OBSERVED:APR 2025
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL62/100
RESOURCES62/100
PERSISTENCE65/100
STEALTH57/100
IMPACT71/100

PRODAFT disclosed on July 25, 2026 that DevMan (tracked as Funky Mantis) operated a highly sophisticated RaaS portal functioning as a full 'CRM for extortion' — integrating payload building, victim lifecycle management, affiliate team creation, automated profit sharing, and victim chat. DevMan emerged in April 2025 as a multi-RaaS affiliate (Qilin, DragonForce, Apos, RansomHub) before pivoting to its own operation, claiming 184 victims before going dark after February 4, 2026 following a doxxing incident by whistleblower 'GangExposed.' LARVA-367 is a former member of Phantom Mantis (The Gentlemen's affiliate cluster) with suspected but unconfirmed infrastructure overlap with The Gentlemen RaaS.

Financial extortion via RaaS; industrialized affiliate management platform development

Centralized RaaS portal with country-specific network targeting, 2-3 day victim completion windows, broker-supplied or self-sourced initial access, automated payout infrastructure, DragonForce code lineage, commodity intrusion access chains

TECHNOLOGY
HEALTHCARE
FINANCIAL SERVICES
PROFESSIONAL SERVICES
GOVERNMENT

Dedicated RaaS web portal (v3 released January 2026 adding structured victim files, lifecycle stages, group creation, invitation checks, deadlines); Telegram coordination; leak site (no new victims post February 4, 2026); nearly 50 US-based victims; suspected connection to The Gentlemen infrastructure (unverified)

FILE DATE: APR 2025
Multi-RaaS Affiliate Phase
LARVA-367 operates as affiliate across Qilin, DragonForce, Apos, and RansomHub before transitioning to standalone operation.
FILE DATE: JUL 2026
PRODAFT Full RaaS Portal Disclosure
Swiss firm PRODAFT publishes extensive report on July 25, 2026 documenting █████████████████████ Mantis portal architecture and operator doxxing incident, with no evidence of resumed operations post-February 2026.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn