Last seven days
- First activity
- Jul 29, 2026
- Last activity
- Jul 29, 2026
- Feed role
- C2 / Distribution
- Host form
- 5 IP / 0 hostnames
DragonForce is a financially motivated ransomware and extortion operation active since late 2023 that operates as a ransomware-as-a-service ecosystem.
Profile source: Mallory opens in a new tabDragonForce
DragonForce is a financially motivated ransomware and extortion operation active since late 2023 that operates as a ransomware-as-a-service ecosystem. It is commonly referred to as DragonForce or Dragon Force, and is also described as a ransomware cartel or ransomware group. Reporting has suggested possible ties to Malaysia, but that attribution is not firmly established. DragonForce has been one of the more active ransomware brands in 2026, with victim claims spanning North America, Europe, the Middle East, Africa, and Asia-Pacific, and with repeated targeting of manufacturing, professional services, healthcare, financial services, technology, telecommunications, hospitality, and other sectors.
DragonForce is associated with double-extortion activity, combining data theft with threats to publish stolen information and, in many cases, file encryption. Public reporting also describes broader coercive behavior beyond conventional ransomware operations, including the use of distributed denial-of-service attacks and website defacements against rival criminal groups. In 2025, DragonForce was reported to have formed a ransomware alliance with LockBit and Qilin, indicating a willingness to cooperate tactically within the criminal ecosystem.
The group is notable both for its operational tempo and for signs of an affiliate-driven model. Other actors have reportedly worked as DragonForce affiliates before launching their own operations, and malware lineage analysis has linked at least one later ransomware program to DragonForce code or locker ancestry. DragonForce has also been observed in the broader healthcare threat landscape in EMEA and in ransomware activity affecting the UK and Ireland, where it ranked among the more active groups during early 2026.
Tradecraft associated with DragonForce includes data exfiltration, encryption for impact, public leak-site shaming, and psychologically manipulative negotiation tactics. Researchers have documented the group’s use of large language models to accelerate extortion workflows and generate more persuasive negotiation messages intended to pressure victims. DragonForce’s messaging has included fabricated or exaggerated claims designed to increase credibility and leverage during ransom discussions.
DragonForce has also appeared in reporting on affiliate tooling and ecosystem overlap. Externally sourced endpoint security disabling tools used in some ransomware intrusions have been observed in DragonForce affiliate activity, although those tools are not unique to the group. Overall, DragonForce should be understood as a prolific criminal ransomware brand with an active extortion program, broad victimology, affiliate participation, and a demonstrated willingness to adopt opportunistic tactics, cross-group collaboration, and AI-assisted social pressure to improve monetization.
C2 tracking
Derp observations, rolling seven-day window
Samples
0f78a658b60f0879acccf0933d9ae8a5d2c188e9f16b8e6f7b01bd0cc9b5c4e1 27215e26b312b8b4f8fc51bdcea6741536dafc9267348284e2259e798aed0e4d 3755718db9d33f4aba2563de454d4530a308b41b1096c904102d08e2101f2020 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 738eacc140159cd81dff41dd16c806eb7c0c8391c256f1738d75d0321f77ba2e MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.