The ransomware has their own “personal account”. Funky Mantis Hackers Acquire CRM for Bandage of Hospitals and Facilities

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
345
Reaction score
508
Deposit
0$
The Funky Mantis ransomware group has turned a regular set of file encryption tools into a full-fledged service: now participants control partners, sell access to networks, and control negotiations with victims. Experts found signs that the operation went beyond the development and was used in at least one real attack.

Funky Mantis, also known as DevMan, runs on the “extortional as a service” model. Administrators have created a closed infrastructure where participants could access compromised networks, collect versions of the malware, negotiate with victims and track payments. Experts analyzed two versions of the web panel and found that from the end of 2025, the service gradually turned into a centralized platform that controlled the attacks.

The first version of the panel included features that allowed you to create malware, financial partition, chat with victims and support services. In January 2026, a new version appeared with a more complex accounting system: operators could create teams, appoint participants, monitor the status of attacks, payment terms and expected income for each victim. This structure made it possible to coordinate several operations at once through a single control center.

Closed messages of the participants revealed the internal organization of the group. Administrators distributed access to networks of different countries, appointed curators and demanded to complete the work in a few days. The correspondence referred to organizations from the health sector, critical infrastructure, commercial sector and government agencies. At the same time, some of these reports only claimed, not confirming successful attacks.


Experts also studied the Windows version of the cryptographer Funky Mantis. The program checks administrator rights, tries to disable Windows protection, stops individual services, deletes shadow copies of the system, searches for network resources and encrypt files on local disks and connected storage. After completing the work, the malware creates a note where it requires paying a ransom, and can delete its own file.

The cipherer uses the Chaha20-Poly1305 algorithm and adds the .devman21 extension to encrypted files. The program is focused on the corporate environment: among the purposes there are documents, databases, backups, virtual machines, source code and files related to medical systems.

Funky Mantis operators separately promoted attacks on critical infrastructure and offered special capabilities for industrial equipment control systems. At the same time, it remains unconfirmed whether operators steal information: the service stated this possibility, but experts have not found tools that output data or file transfer confirmation.

To protect against such attacks, Catalyst Prodaft experts recommend tracking not individual files or hashes, but the sequence of actions of attackers. A dangerous sign may be an unusual login through remote access, subsequent use of privileged accounts, SMB activity, change group policies, disconnection of protective equipment and removal of recovery mechanisms. This approach better detects the preparation of the attack before the launch of the ransomware.
 
Top Bottom