DevMan is a ransomware-as-a-service (RaaS) operation that emerged in April 2025, initially as an affiliate for Qilin, DragonForce, Apos, and RansomHub before launching its own platform. The group operates a centralized web portal for payload building, victim management, and affiliate payouts. It has claimed 184 victims, primarily in the U.S., targeting technology, healthcare, financial services, professional services, and government sectors. The group developed a specialized SCADA locker for critical infrastructure attacks.