DragonForce Ransomware | Group Profile & Attack Analysis | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


DragonForce ransomware is a ransomware-as-a-service (RaaS) operation that began as a pro-Palestine hacktivist collective based in Malaysia before pivoting to ransomware, and has since grown into one of the most disruptive extortion brands in the ransomware landscape. In March 2025, DragonForce publicly restructured itself as a ransomware cartel, and by that autumn it had formed a formal coalition with two of the biggest names in ransomware, LockBit and Qilin, a partnership researchers say is designed to share techniques, resources, and infrastructure across all three groups. The group’s real-world impact is already measurable: the DragonForce-linked breach of UK retailer Marks & Spencer alone dropped the company’s statutory profit from £391.4 million to just £3.4 million. It cost roughly £136 million in direct response expenses. This guide breaks down who DragonForce is, how its cartel-and-affiliate model works, the attacks it has been linked to, and how organizations can defend against it.

What Is DragonForce Ransomware?

DragonForce ransomware is a ransomware-as-a-service (RaaS) operation whose affiliates deploy DragonForce’s encryptor to extort victim organizations, typically by locking systems and threatening to leak stolen data unless a ransom is paid. Rather than running attacks itself, DragonForce builds and rents out the infrastructure, leak sites, and encryptors, as well as negotiation tooling, that other criminal groups use to carry out their own campaigns under the DragonForce brand or their own.

Origins and First Appearance

DragonForce first appeared in August 2023 as a pro-Palestine hacktivist collective operating under the name DragonForce Malaysia, targeting government and commercial organizations across the Asia-Pacific region and the US, including Honolulu’s transit authority, the Government of Palau, Coca-Cola Singapore, and the Ohio State Lottery. Over the following year, the group shifted from ideologically motivated hacktivism to a full ransomware-as-a-service operation, marking the start of its current identity as a financially driven RaaS brand rather than a protest-oriented hacking crew.

DragonForce vs. Other RaaS Groups

What separates DragonForce from established RaaS operators like LockBit and Qilin is its white-label model: affiliates can run DragonForce’s ransomware under their own branding rather than DragonForce’s, making individual attacks harder to attribute and giving lower-skilled criminals a low-barrier way into ransomware operations. DragonForce also offers affiliates an unusually generous 80% cut of ransom profits along with customizable encryptors, a structure built to attract affiliates quickly rather than compete purely on technical sophistication the way Qilin has, which logged over 437 confirmed victims in 2025 through its own direct operations. That recruitment-first strategy is also what let DragonForce absorb the RansomHub RaaS toolkit after it went dark in March 2025, folding a rival’s technology and affiliate base directly into its own.

The DragonForce Ransomware Cartel Model

The DragonForce ransomware cartel is a coalition structure the group announced in 2025, in which competing ransomware operators agree to share infrastructure, techniques, and affiliates rather than compete for the same targets. It marks a shift from the traditional RaaS model of isolated, competing gangs toward a more criminal-supply-chain model, where tools and access brokers move freely between brands.

How the Affiliate/Cartel Structure Works

DragonForce’s cartel model runs on affiliate recruitment: outside hackers pay to access DragonForce’s encryptors and leak-site infrastructure, then keep the majority of whatever ransom they collect. As of October 2025, DragonForce had lowered its onboarding requirements even further, dropping background checks, prior work history requirements, and its $10,000 deposit in favor of a flat $500 non-refundable registration fee. That low barrier to entry is deliberate: the easier it is to join, the faster DragonForce’s affiliate network grows, and the harder it becomes for defenders to attribute any single attack to a single identifiable group rather than a rotating cast of affiliates.

DragonForce’s Alliance with LockBit, Qilin, and Scattered Spider

In September 2025, DragonForce publicly proposed a formal coalition with LockBit and Qilin, two of the most established ransomware groups, posting on dark web forums that the arrangement would allow the groups to “dictate market conditions” together rather than compete. LockBit agreed, and by Q3 2025 threat intelligence firm ReliaQuest was tracking shared infrastructure, tools, and data-leak resources connecting all three operations, a coalition analysts say could help LockBit rebuild affiliate trust after last year’s law enforcement takedown while expanding the combined group’s reach into sectors previously considered lower risk. Separately, DragonForce maintains a working relationship with Scattered Spider, a loosely organized network of English-speaking hackers known for social-engineering-based intrusions; Scattered Spider affiliates use DragonForce’s ransomware and infrastructure to finish attacks they’ve already gained access for, paying DragonForce a cut of any resulting ransom.

Notable DragonForce Attacks

DragonForce’s most damaging confirmed attacks are the spring 2025 breaches of three major UK retailers, Marks & Spencer, the Co-op, and Harrods, carried out with the social-engineering group Scattered Spider, alongside a fast-growing global campaign that has since claimed hundreds of victims across professional services, manufacturing, and technology.

Notable DragonForce Attacks

The M&S, Co-op, and Harrods Breaches

Marks & Spencer was the first and worst-hit of the three, with attackers gaining initial network access as early as February 2025 by impersonating an employee to a third-party service desk and triggering a password reset. This foothold let them steal the company’s Active Directory credential database and later deploy the DragonForce encryptor against its VMware ESXi servers. The attack halted warehouse operations, sent hundreds of staff home, and cost M&S roughly £136 million in direct response expenses while dropping the retailer’s statutory profit from £391.4 million to £3.4 million for the year. Co-op and Harrods were hit within weeks of M&S in what researchers concluded was a coordinated campaign, with all three intrusions showing tradecraft consistent with Scattered Spider gaining access before finishing the job with DragonForce’s ransomware payload.

Timeline of Major Incidents (2025–2026)

DragonForce’s attack volume has grown sharply since its March 2025 cartel rebrand: the group absorbed the rival RansomHub platform’s tools and affiliates after RansomHub collapsed that April, then carried out the UK retail spree through May, and by December 2025 was posting a then-record 35 new victims in a single month, including an attack using a custom “Backdoor.Turn” implant that abused Microsoft Teams infrastructure to hide its command-and-control traffic. Growth continued into 2026; DragonForce logged 101 new victims in the first quarter alone, a 29% jump from the previous quarter, and by the end of August 2026 the group’s leak site had publicly claimed 645 victims across 65 countries since it began operating, concentrated in professional services, manufacturing, and technology.

Tactics, Techniques, and Procedures

DragonForce attacks follow a fairly consistent playbook: gain access via stolen credentials or exploited remote access software, move across the network using built-in Windows administration tools, then encrypt and exfiltrate data before demanding payment. Because affiliates operate independently within DragonForce’s infrastructure, the exact tooling varies slightly across intrusions, but the core attack chain maps closely to known MITRE ATT&CK techniques.

Tactics, Techniques, and Procedures

Initial Access and Social Engineering

DragonForce affiliates most often gain access to a network through valid stolen credentials, phishing, or by exploiting internet-facing remote-access software rather than sophisticated zero-days. In several confirmed cases, the group has exploited vulnerabilities in the SimpleHelp remote monitoring and management tool, including a critical path-traversal flaw and an arbitrary file-upload bug that leads to remote code execution, to gain a foothold and exfiltrate device, account, and network data directly from the victim’s management console. When affiliates work alongside Scattered Spider, initial access instead comes through help desk social engineering, as in the Marks & Spencer breach, where attackers impersonated an employee to obtain a password reset for a privileged account.

PsExec, WMI, and LOLBAS Abuse

Once inside, DragonForce affiliates favor living-off-the-land techniques over custom malware to avoid tripping endpoint defenses. PsExec and Windows Management Instrumentation (commands such as wmic /node: TARGET process call create) are used to push the ransomware executable to multiple machines and trigger it remotely. At the same time, tools like AdFind handle network and account discovery, and registry hive dumping or credential-viewer utilities pull stored passwords. This reliance on legitimate, pre-installed Windows administration tools, rather than external malware that antivirus tools are tuned to catch, is what lets DragonForce affiliates fan out across dozens of endpoints before anyone notices.

Known Indicators of Compromise (IOCs)

DragonForce intrusions leave a recognizable technical footprint that defenders can monitor directly. The ransomware deletes event logs and turns off security tooling to erase its tracks (MITRE ATT&CK T1070 and T1562), creates scheduled tasks or registry run keys for persistence across reboots, and encrypts files using AES-256 (T1486) after generating a unique key pair per infected machine. On the network side, security researchers have linked the DragonForce campaign infrastructure to command-and-control IP addresses, including 2.147.68.96, 185.59.221.75, and 69.4.234.20, with some early infrastructure traced back to Iran, suggesting the group rents or shares hosting across multiple regions rather than operating from a single fixed base.

How a DragonForce Ransomware Attack Unfolds

A DragonForce ransomware attack follows a predictable sequence: initial access, lateral movement and data theft, then encryption and a public ransom demand. However, the group’s affiliates have shown they can stretch that timeline for months when it works in their favor.

How a DragonForce Ransomware Attack Unfolds

Infiltration to Encryption Timeline

Most ransomware operations move from initial access to encryption within days; industry-wide analysis puts the median dwell time at just four to five days before attackers pull the trigger on file encryption. DragonForce affiliates don’t always follow that pattern with the group’s Backdoor. Turn implant, which tunnels command-and-control traffic through legitimate Microsoft Teams infrastructure, researchers have confirmed dwell times of up to two months on victim networks before ransomware deployment, since the traffic blends into normal business communications and generates no suspicious outbound connections for network monitoring to catch. That patience gives affiliates time to fully map the network, identify the most damaging data to steal, and turn off backups before ever triggering the encryption stage that would tip off defenders.

Double-Extortion and Dark Web Leak Sites

DragonForce runs a double-extortion model, meaning affiliates steal a victim’s data before encrypting it, then use both levers, locked systems and the threat of a public data leak, to pressure payment. Stolen files are staged for publication on DragonForce’s dedicated dark web leak site. Affiliates targeting organizations with more than $15 million in annual revenue can pay into the group’s “Data Analysis Service,” which automates a risk audit of the stolen dataset and generates tailored extortion scripts, draft executive letters, and regulatory-threat talking points to speed up payment. This combination of encryption and reputational leverage is why encryption alone is no longer the main danger in a DragonForce incident; even organizations that restore from backup still face the exposure risk of their data appearing on the group’s leak site if a ransom goes unpaid.

How to Protect Your Organization from DragonForce

Defending against DragonForce ransomware means closing the access points affiliates rely on most: exposed remote-access tools, weak help-desk verification, and unpatched RMM software, while building the visibility to catch an intrusion during its weeks-long dwell time rather than after encryption hits.

How to Protect Your Organization from DragonForce

Detection and Monitoring Recommendations

Because DragonForce affiliates favor living-off-the-land tools like PsExec and WMI over custom malware, traditional antivirus often won’t flag their activity; detection depends on watching for behavior that’s abnormal even when the tools themselves are legitimate, such as WMI process creation across many machines in a short window, AdFind-style network enumeration, or scheduled tasks appearing on servers that shouldn’t need them. Patching internet-facing remote-management software promptly matters just as much: DragonForce has exploited known SimpleHelp vulnerabilities to gain footholds, so unpatched RMM tools are a direct route in. Enforcing MFA on all administrative and remote access and training help-desk staff to verify identity before processing password resets closes the specific social-engineering path that Scattered Spider used to breach Marks & Spencer.

How Dark Web Monitoring Helps Catch Early Warning Signs

DragonForce’s leak site is often where an organization first learns it’s been breached, sometimes weeks or months after the actual intrusion, once an affiliate is ready to pressure payment. Continuous dark web monitoring shortens that gap by scanning leak sites, criminal forums, and stolen-credential marketplaces for mentions of your organization, employee credentials, or exposed systems before a public leak-site listing forces your hand. DeXpose’s dark web monitoring tracks these sources in real time, giving security teams a chance to respond, reset compromised credentials, and contain an incident before it reaches the extortion stage.

Frequently Asked Questions (FAQ’s)

Is DragonForce the same as LockBit or Qilin?

No, they’re separate ransomware groups that formed a cartel-style alliance in 2025 to share infrastructure and affiliates. Each still operates its own ransomware and leak site.

Has law enforcement taken down DragonForce?

No confirmed takedown has occurred. As of mid/late 2026, the group remains active and continues to post new victims on its leak site.

Should a company pay a DragonForce ransom demand?

Most law enforcement and incident-response guidance discourages payment because it doesn’t guarantee data deletion and instead funds further attacks. Each case should be assessed with legal and IR counsel.

How does DragonForce typically first gain access?

Most commonly through stolen credentials, phishing, or exploitation of remote-access software, though some attacks involve help desk social engineering to reset privileged account passwords.

——————————————————–


Click Here For The Original Source.

.........................