The Ransomware Crew Has a Support Desk, a Payouts Page, and a Two-Day Deadline for Its Staff
- Patrick Duggan
- 2 hours ago
- 4 min read
PRODAFT has published research on the DevMan ransomware-as-a-service operation, which they track as Funky Mantis. The interesting part is not the malware. It is the admin console.
The portal, in one list: payload build generation, finance, victim chat, support tickets, victim records, team creation, and affiliate payouts.
Read that again as a product spec and tell me it isn't a SaaS company. There is a build pipeline. There is a billing module. There is a CRM — they call them victim files, with lifecycle stages. There is a helpdesk, for the affiliates. There is team management, so a crew can onboard its own people. Version 3, shipped January 2026, added structured victim records, per-victim deadlines, group creation, and invitation checks.
Invitation checks. They have an onboarding flow.
Two details that change what you should do
Most RaaS coverage stops at "80-20 revenue split" — which is true here, with ransom funds routed to two wallets, one for the affiliate and one for the program. That is the headline number and it is the least useful thing in the report.
These two are the useful ones.
First: access brokerage is built into the platform. The administrators offer country-specific "networks," and when an affiliate takes a job the portal asks whether they will use their own access or access supplied by the program. Initial access is inventory now, stocked and issued from behind the counter.
That reframes your exposed edge. Your unpatched VPN appliance, your internet-facing RDP, your stale contractor VPN account — those are not just your risk. They are somebody's stock. There is a market where the thing your organization forgot about has a listed price and a country tag, and an affiliate can be handed it on a Tuesday without ever having found it themselves.
Second: the platform imposes two-to-three-day completion windows. The program gives an affiliate a deadline per victim.
That is the number a defender should actually plan against. All the industry talk about mean dwell time in weeks describes a patient, exploratory intruder. An affiliate who has been handed working access and has 48 to 72 hours to produce a payout does not do reconnaissance. They do not live off the land quietly for a month. They land, escalate, find the file shares, exfiltrate, and encrypt — because their pay depends on doing it before the clock runs out.
Your detection budget is days, not weeks. If your response plan assumes you will notice unusual behaviour over a fortnight of low-and-slow activity, it is calibrated for the wrong adversary. The platform has industrialized urgency.
Why the bureaucracy is the threat
We have watched this trajectory all year. NightSpire started as a closed operator-driven crew in early 2025 and announced an affiliate program in 2026 — the same transition, one rung down. The GandCrab lineage did it years ago and everyone learned the wrong lesson from it, which was that RaaS is a distribution model.
RaaS is not a distribution model. It is labor management, and that is what makes it dangerous.
A skilled intruder is rare and expensive. A portal with a build wizard, supplied access, a support desk, and a deadline does not need a skilled intruder — it needs somebody who can follow a workflow. The build generation means the affiliate never touches malware development. The supplied access means they never have to find a way in. The support desk means when they get stuck, somebody helps. The deadline means they do not get to dawdle.
That is a machine for converting mediocre operators into competent-looking attacks, and it scales in a way talent never does. Every piece of infrastructure that removes a skill requirement widens the pool of people who can hurt you.
What to do this week
Recalculate your response window to 72 hours. Ask, concretely: if someone had valid credentials in our environment right now, what would we detect in the first two days? Not in thirty. If the answer is "the encryption," you have no window at all.
Inventory what a broker could already be selling. Exposed RDP, SSL-VPN appliances behind on patches, dormant contractor accounts, service accounts with stale passwords, anything of yours reachable from the internet with a login prompt. You are not hunting an intruder here; you are auditing your own listing on somebody's shelf.
Assume the initial access is legitimate. Supplied access means valid credentials, so exploit detection will not fire. Your signal is behavioural — an account authenticating from a new country, touching file shares it has never touched, at a volume it has never produced.
Back up like the clock is 48 hours. Offline, tested, and restorable inside the window the affiliate is working against. A backup you have never restored is a plan, not a control.
We have no attributed DevMan or Funky Mantis indicators in our feed as of this writing — PRODAFT's research is infrastructure and process analysis rather than a published indicator set, and we are not going to manufacture receipts we do not have. If indicators surface we will harvest and publish them free, as usual. What we can hand you today is the shape, and the shape says: days, not weeks.
We are 95 percent confident the deadline mechanic spreads to other programs, because it demonstrably works — it converts an affiliate's incentive into velocity, and velocity is what beats detection. The remaining five percent is that the pressure produces sloppier operators who trip more alarms. That would be a gift, and it is not how I would bet.
Credit to PRODAFT for the platform research, and to Analyst1 for their earlier work on DevMan's move from affiliate to operator.
Free IP, domain, hash, and malicious-package blocklists at analytics.dugganusa.com. No key, no sales call.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
