Funky Mantis Ransomware Runs a Full RaaS Platform

Funky Mantis ransomware affiliate panel coordinating DevMan locker deployments against healthcare and critical infrastructure targets

The Funky Mantis extortion group has transformed an ordinary file-encryption toolkit into a fully fledged commercial service. Members now manage affiliates, sell access to compromised networks, and oversee negotiations with victims.

Researchers have found indications that the operation has moved beyond development. It has been used in at least one genuine attack.

An Operation Built Like a Business

Funky Mantis, also known as DevMan, operates under the ransomware-as-a-service model. Its administrators constructed a closed infrastructure serving several purposes at once.

Within it, participants could obtain access to compromised networks, assemble builds of the malicious program, negotiate with victims, and track payments. Researchers examined two versions of the web panel.

Their analysis established a clear trajectory. From late 2025 onwards, the service gradually matured into a centralised platform that directed attacks.

From Toolkit to Command Centre

The first iteration of the panel offered malware creation functions, a financial section, a victim chat, and a support desk. Serviceable, but rudimentary.

January 2026 brought a considerably more sophisticated accounting system. Operators could now form teams, assign members, and monitor the status of each attack alongside payment deadlines and expected revenue per victim.

Such a structure permitted the coordination of several operations simultaneously through a single control centre.

What Internal Chatter Revealed

Private messages among participants exposed the group’s internal organisation. Administrators distributed access to networks in various countries, appointed handlers, and demanded that work conclude within a few days.

The correspondence named organisations across healthcare, critical infrastructure, the commercial sector, and government bodies. Some of these claims, however, remained mere assertions. Participants never substantiated successful attacks in every case.

Inside the Windows Locker

Researchers also dissected the Windows build of the Funky Mantis encryptor. Its behaviour follows a familiar but methodical sequence.

The program verifies administrator privileges and attempts to disable Windows protections. It then halts selected services, deletes shadow copies of the system, hunts for network resources, and encrypts files on local drives and attached storage.

Upon completion, the malware drops a note demanding ransom. It may also delete its own executable.

Encryption and Target Selection

The locker employs the ChaCha20-Poly1305 algorithm and appends the extension .devman21 to encrypted files.

Its orientation is unmistakably corporate. Targets include documents, databases, backups, virtual machines, source code, and files associated with medical systems.

Ambitions and Unanswered Questions

Funky Mantis operators promoted attacks against critical infrastructure separately. They advertised special capabilities aimed at industrial control systems.

One claim remains unverified, however. The service advertised data theft, yet researchers discovered neither exfiltration tooling nor evidence that files were ever transferred out.

How Defenders Should Respond

Catalyst Prodaft specialists recommend a behavioural approach to detection. Rather than chasing individual files or hashes, defenders should watch for the sequence of adversary actions.

Several signals deserve particular attention. An unusual login through remote access is one. Subsequent use of privileged accounts is another.

Beyond those, watch for SMB activity, modifications to group policy, the disabling of security tooling, and the removal of recovery mechanisms. This approach identifies attack preparation far more reliably, and crucially, before the encryptor ever runs.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply