Cybersecurity researchers have uncovered new details about DevMan RaaS, a ransomware platform built for affiliates. The operation provides a dedicated web portal for managing ransomware campaigns. Moreover, the platform helps affiliates create malware, monitor victims, and track payments. Researchers believe this setup makes cybercrime more efficient. As a result, attackers can organize operations from one central dashboard.
According to a recent report, the platform combines several important features. For example, it offers payload creation, financial tracking, victim communication, and technical support. Furthermore, affiliates can manage multiple attacks without relying on messaging apps. The system also includes deadline tracking and team management tools. Therefore, the platform supports large-scale ransomware campaigns with greater efficiency.
DevMan RaaS Has Evolved Over Time
Researchers found that the ransomware group first appeared in 2025. Initially, the operators worked with other ransomware programs as affiliates. However, they later launched their own ransomware service. Security experts also noticed that the malware shares technical similarities with earlier ransomware families. Therefore, they believe the developers reused proven techniques while expanding their own platform.
The group also gained attention through public interviews and online activity. For example, the operators openly discussed their ransomware capabilities. They even claimed to develop malware that could target industrial systems. Although researchers could not verify every statement, the claims raised serious concerns. As a result, many organizations increased monitoring of similar threats.
Affiliate Portal Simplifies Cybercrime
The latest version of the DevMan RaaS portal introduces several new management features. Affiliates can now organize victims into structured records. In addition, they can create teams and assign responsibilities. The platform also tracks ransom payments and project deadlines. Therefore, affiliates can manage several attacks at the same time.
Researchers also observed strict internal rules. New affiliates receive guidance from experienced members after their first successful attack. However, inactive members may lose access after one month. Team creation also requires approval from supervisors. Consequently, the operators maintain strong control over their criminal network.
Clear Roles Improve Coordination
The report identifies several different roles inside the ransomware operation. One person acts as the administrator and oversees daily activities. Other members coordinate network access and technical support. Meanwhile, experienced operators supervise affiliates during attacks. This structure helps maintain consistent operations across multiple campaigns.
The administrators also control victim negotiations. For example, they may replace an affiliate during ransom discussions if needed. Furthermore, they enforce deadlines and operational standards. Therefore, affiliates have limited independence throughout each campaign. This approach helps protect profits while reducing internal disputes.
Victims and Targeting Strategy
Researchers estimate that the ransomware group has claimed more than 180 victims. Many organizations operated in technology, healthcare, finance, government, and professional services. Furthermore, a large share of victims came from the United States. However, researchers have not confirmed any new victims since early 2026.
The group’s targeting rules also reveal clear priorities. Affiliates may attack organizations outside selected regions. However, they must avoid certain healthcare organizations involving children. The policy also discourages releasing personal information belonging to minors. Nevertheless, the operators openly encourage attacks against critical infrastructure.
Modern Malware Features Increase Risk
The ransomware builder allows affiliates to generate malware for Windows, Linux, and ESXi systems. Once deployed, the malware performs several harmful actions. For example, it disables security tools and stops important services. It also clears event logs and searches local and network storage. Therefore, the malware can spread while reducing detection opportunities.
The ransomware uses strong encryption to lock files. Smaller files receive complete encryption. However, larger files undergo partial encryption to improve speed. The malware also creates ransom notes and may remove itself afterward. As a result, recovery becomes much more difficult without proper backups.
Insider Allegations Raise More Questions
The report also mentions allegations involving a security researcher. A former employee claimed another researcher shared law enforcement communications with the ransomware operator. According to public statements, the researcher informed the attacker about an ongoing investigation. However, the organization stated that it found no evidence of illegal activity.
The organization described the incident as poor judgment rather than malicious intent. Nevertheless, it strengthened internal policies after reviewing the matter. Former staff members continue to disagree with that conclusion. Therefore, discussions about insider risks remain active within the cybersecurity community.
How to Reduce the Risk of DevMan RaaS Attacks
Organizations should strengthen remote access security before attackers gain entry. For example, phishing-resistant multi-factor authentication can stop many account takeover attempts. In addition, continuous security monitoring helps detect unusual activity before ransomware spreads.
Regular vulnerability assessments and managed detection services also improve visibility across networks. Finally, secure offline backups and rapid incident response planning help businesses recover faster if an attack occurs.
Sleep well, we got you covered.

