Skip to content

DragonForce

DragonForce is a financially motivated ransomware and extortion operation active since late 2023 that operates as a ransomware-as-a-service ecosystem.

Profile source: Mallory opens in a new tab

DragonForce

Family profile

DragonForce is a financially motivated ransomware and extortion operation active since late 2023 that operates as a ransomware-as-a-service ecosystem. It is commonly referred to as DragonForce or Dragon Force, and is also described as a ransomware cartel or ransomware group. Reporting has suggested possible ties to Malaysia, but that attribution is not firmly established. DragonForce has been one of the more active ransomware brands in 2026, with victim claims spanning North America, Europe, the Middle East, Africa, and Asia-Pacific, and with repeated targeting of manufacturing, professional services, healthcare, financial services, technology, telecommunications, hospitality, and other sectors.

DragonForce is associated with double-extortion activity, combining data theft with threats to publish stolen information and, in many cases, file encryption. Public reporting also describes broader coercive behavior beyond conventional ransomware operations, including the use of distributed denial-of-service attacks and website defacements against rival criminal groups. In 2025, DragonForce was reported to have formed a ransomware alliance with LockBit and Qilin, indicating a willingness to cooperate tactically within the criminal ecosystem.

The group is notable both for its operational tempo and for signs of an affiliate-driven model. Other actors have reportedly worked as DragonForce affiliates before launching their own operations, and malware lineage analysis has linked at least one later ransomware program to DragonForce code or locker ancestry. DragonForce has also been observed in the broader healthcare threat landscape in EMEA and in ransomware activity affecting the UK and Ireland, where it ranked among the more active groups during early 2026.

Tradecraft associated with DragonForce includes data exfiltration, encryption for impact, public leak-site shaming, and psychologically manipulative negotiation tactics. Researchers have documented the group’s use of large language models to accelerate extortion workflows and generate more persuasive negotiation messages intended to pressure victims. DragonForce’s messaging has included fabricated or exaggerated claims designed to increase credibility and leverage during ransom discussions.

DragonForce has also appeared in reporting on affiliate tooling and ecosystem overlap. Externally sourced endpoint security disabling tools used in some ransomware intrusions have been observed in DragonForce affiliate activity, although those tools are not unique to the group. Overall, DragonForce should be understood as a prolific criminal ransomware brand with an active extortion program, broad victimology, affiliate participation, and a demonstrated willingness to adopt opportunistic tactics, cross-group collaboration, and AI-assisted social pressure to improve monetization.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 29, 2026
Last activity
Jul 29, 2026
Feed role
C2 / Distribution
Host form
5 IP / 0 hostnames

Leading locations

  • HK2
  • US2
  • CH1

Leading providers

  • ChangLian Network Technology Co., Limited1
  • Cox Communications Inc.1
  • DEDIK SERVICES LIMITED1
  • Hong Kong Communications International Co., Limited1
  • XNNET LLC1

Infrastructure traits

  • Hosting 3

Samples

Recent associated samples

MITRE ATT&CK

DragonForce in ATT&CK

111 distinct techniques

Techniques

111 techniques
T1486 Data Encrypted for Impact T1580 Cloud Infrastructure Discovery T1195 Supply Chain Compromise T1005 Data from Local System T1567 Exfiltration Over Web Service T1657 Financial Theft T1565 Data Manipulation T1598 Phishing for Information T1041 Exfiltration Over C2 Channel T1537 Transfer Data to Cloud Account T1074 Data Staged T1033 System Owner/User Discovery T1136 Create Account T1212 Exploitation for Credential Access T1082 System Information Discovery T1021.002 SMB/Windows Admin Shares T1574.011 Services Registry Permissions Weakness T1555 Credentials from Password Stores T1021.001 Remote Desktop Protocol T1560 Archive Collected Data T1539 Steal Web Session Cookie T1219 Remote Access Tools T1098 Account Manipulation T1068 Exploitation for Privilege Escalation T1105 Ingress Tool Transfer T1112 Modify Registry T1078 Valid Accounts T1569 System Services T1190 Exploit Public-Facing Application T1562 Impair Defenses T1090 Proxy T1548 Abuse Elevation Control Mechanism T1071 Application Layer Protocol T1210 Exploitation of Remote Services T1003.001 LSASS Memory T1562.001 Disable or Modify Tools T1027.007 Dynamic API Resolution T1140 Deobfuscate/Decode Files or Information T1070 Indicator Removal T1083 File and Directory Discovery T1059.001 PowerShell T1027 Obfuscated Files or Information T1018 Remote System Discovery T1135 Network Share Discovery T1078.002 Domain Accounts T1016 System Network Configuration Discovery T1482 Domain Trust Discovery T1547.001 Registry Run Keys / Startup Folder T1560.001 Archive via Utility T1490 Inhibit System Recovery T1497.001 System Checks T1053 Scheduled Task/Job T1070.001 Clear Windows Event Logs T1036 Masquerading T1543.003 Windows Service T1649 Steal or Forge Authentication Certificates T1046 Network Service Discovery T1007 System Service Discovery T1055 Process Injection T1070.004 File Deletion T1572 Protocol Tunneling T1090.002 External Proxy T1647 Plist File Modification T1562.004 Disable or Modify System Firewall T1014 Rootkit T1090.003 Multi-hop Proxy T1570 Lateral Tool Transfer T1057 Process Discovery T1059 Command and Scripting Interpreter T1071.001 Web Protocols T1569.002 Service Execution T1003 OS Credential Dumping T1567.002 Exfiltration to Cloud Storage T1133 External Remote Services T1204 User Execution T1021 Remote Services T1553.005 Mark-of-the-Web Bypass T1110 Brute Force T1556 Modify Authentication Process T1110.003 Password Spraying T1218 System Binary Proxy Execution T1027.002 Software Packing T1491.001 Internal Defacement T1498 Network Denial of Service T1020 Automated Exfiltration T1491 Defacement T1072 Software Deployment Tools T1203 Exploitation for Client Execution T1087 Account Discovery T1006 Direct Volume Access T1213 Data from Information Repositories T1136.001 Local Account T1550 Use Alternate Authentication Material T1048 Exfiltration Over Alternative Protocol T1566.004 Spearphishing Voice T1558 Steal or Forge Kerberos Tickets T1591 Gather Victim Org Information T1621 Multi-Factor Authentication Request Generation T1589 Gather Victim Identity Information T1566 Phishing T1047 Windows Management Instrumentation T1053.005 Scheduled Task T1566.001 Spearphishing Attachment T1564.003 Hidden Window T1204.002 Malicious File T1134 Access Token Manipulation T1489 Service Stop T1571 Non-Standard Port T1189 Drive-by Compromise T1553.002 Code Signing T1059.003 Windows Command Shell

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.