Credential Theft
- Mimikatz
DragonForce is a ransomware family and ransomware-as-a-service operation active since at least 2025 that has been associated with double-extortion intrusions against organizations worldwide.
Profile source: Mallory opens in a new tabDragonForce
DragonForce is a ransomware family and ransomware-as-a-service operation active since at least 2025 that has been associated with double-extortion intrusions against organizations worldwide. It has targeted sectors including manufacturing, business services, education, healthcare, retail, and industrial organizations, and has also been linked in some reporting to activity involving Scattered Spider. In 2025 the operation rebranded itself as a "ransomware cartel," allowing affiliates to build and run their own branded variants on shared DragonForce infrastructure, reflecting a broader affiliate-driven operating model.
DragonForce intrusions have been observed following compromise of valid accounts, exploitation of internet-facing systems and edge appliances, and abuse of remote-access software. Reported cases include deployment after compromise of Citrix NetScaler environments via session hijacking tied to CVE-2025-5777, as well as incidents where attackers installed remote-management tools such as AnyDesk to establish access before ransomware execution. In some environments, operators moved from initial access to ransomware deployment in under an hour, while other intrusions involved long dwell time and extensive hands-on-keyboard activity.
The malware and its operators have demonstrated mature post-compromise tradecraft. Observed behaviors include privilege escalation, creation of rogue user accounts, modification of firewall and security settings, credential theft, lateral movement using administrative tooling, network reconnaissance and scanning, data exfiltration, and encryption of victim systems. DragonForce activity has also been associated with defense evasion techniques such as log clearing, disabling or impairing security controls, and bring-your-own-vulnerable-driver-style evasion. In one notable intrusion chain, operators used a Go-based backdoor known as Backdoor.Turn to conceal command-and-control traffic within legitimate Microsoft Teams TURN relay traffic, blending malicious communications with normal enterprise network activity.
DragonForce has been repeatedly identified among the more active ransomware brands in 2025 and 2026 victim-leak reporting. Its ecosystem appears to include affiliates and derivative operations, and some researchers have assessed malware lineage connections between DragonForce and later ransomware projects such as DevMan. The operation is notable for combining conventional ransomware objectives with increasingly sophisticated access, persistence, and evasion tradecraft.
3a514e164db30acdb3063eb79a23aa4ff0410358a0d9dbd0dff3113d9c744ca799be93aa4c34b39fedcd37663c34511f2dd7cd2bf15eec7d62689435fca9c49c3c311cabe7de6a8c104f8f10541d392d12e22f588f6128cf1a042d1122556cd2e4a4fc96188310b7b07e7c0525b5c0aa15634dc79981e7fba25fb8530cedb9818bcd83352bbd52ca7bda998a52dd0e5c6c755a742f2b2e5c1820f57d0338365f1C054B722BCBF41A918EF3C485712742088F5C3E81B2FDD91ADEA6BA55F4A856D90A65E99D2045.135.232.195Reported operators
Criminal complaints against alleged Scattered Spider members and public reports reveal collaboration of the subclusters with ALPHV/Blackcat and Dragonforce.
Devman is a ransomware operator, believed to be located in Russia, who uses modified DragonForce code built on top of the leaked Conti source code.
The DragonForce Ransomware Group, first detected in December 2023, developed its own ransomware based on LockBit 3.0 (Black) and Conti Ransomware code.
When DragonForce emerged in August 2023, it offered a traditional RaaS scheme. On March 19, 2025, the group announced a rebrand as a ‘cartel’ to expand its reach, hoping to emulate the success of LockBit and other mature ransomware-as-a-service (RaaS) groups.
DragonForce posted 101 victims in Q1 2026 (an increase of 29% compared to Q4 2025), with a steep climb from 10 victims in January to 35 in February and 56 in March.
“DragonForce ransomware was first identified in August 2023… DragonForce has two ransomware variants - one based on LockBit Ransomware and another based on the Conti Ransomware variant.”
“DragonForce ransomware was first identified in August 2023… DragonForce has two ransomware variants - one based on LockBit Ransomware and another based on the Conti Ransomware variant.”
The final phase involves deploying ransomware. Recently we have seen the group prefer the DragonForce variant, particularly targeting virtualised environments.
Exploited software
MITRE ATT&CK
Reporting
Researchers say DevMan, also tracked as Funky Mantis, operated a centralized ransomware-as-a-service platform with a dedicated affiliate portal for payload generation, victim management, ransom negotiation, earnings tracking, and internal coordination. PRODAFT reported the group was active from late 2025 into early 2026, used an 80/20 affiliate revenue split, and claimed 184 victims, with the heaviest concentration in the United States across technology, healthcare, financial services, professional services, and government. The operation explicitly pursued hospitals, critical infrastructure, the public sector, and law enforcement, and advertised a separate encryptor for SCADA environments, underscoring its focus on high-impact targets. Technical reporting links DevMan’s malware to DragonForce/Conti lineage while showing the operation evolved beyond a simple variant. Earlier analysis described a DragonForce-based sample marked by the .DEVMAN extension, SMB share probing, rapid encryption, and a builder flaw that encrypted its own ransom notes; later reporting identified a Rust-based Devman Locker using ChaCha20-Poly1305, appending .devman21, dropping RESTORE_FILES.txt, mounting network shares, disabling defenses, deleting shadow copies and event logs, and inhibiting recovery. The latest portal version reportedly supports Windows, Linux, and ESXi lockers and includes features for privilege checks, lateral movement, and security-tool impairment, indicating a mature and centrally managed extortion operation.
Arctic Wolf Labs reported multiple intrusions in which threat actors exploited CVE-2026-0257 to gain initial access to victim networks and then quickly deployed Qilin ransomware. The incidents, observed across separate organizations, followed a consistent pattern in which perimeter compromise was followed by rapid movement toward broad encryption activity. The reporting indicates the attacks were distinct events but shared the same intrusion chain, linking exploitation of CVE-2026-0257 directly to domain-wide ransomware deployment. Arctic Wolf attributed the post-compromise activity to Qilin operations, highlighting the vulnerability as a recurring entry point in recent ransomware incidents.
Qilin ransomware has emerged as one of the most active cybercrime threats, with NCC Group identifying it as the most prolific ransomware group for the fifth consecutive quarter as global ransomware incidents climbed to 2,229 in Q2 2026. The group, also tracked as Agenda or Qilin Locker, operates a double-extortion RaaS model and has concentrated on high-GDP Western countries while reportedly avoiding CIS member states. Manufacturing and other industrial sectors have been hit hardest, alongside business services, technology, healthcare, and finance, with North America remaining the most affected region and Belgium reporting at least 15 alleged Qilin compromises that disrupted operations and exposed sensitive corporate data.
Ransomware and cyber-extortion activity rose again in Q2 2026, with industry reporting showing more than 2,250 publicly named victims across roughly 90 active groups and nearly 100 countries. GuidePoint Security’s GRIT report counted 2,279 victims, up 7% from the prior quarter and 43% year over year, while ReliaQuest recorded 2,252 victims and found the United States accounted for about 49% of observed activity. Qilin remained a leading force in one dataset for a fifth straight quarter, while The Gentlemen surged into the top tier and was ranked the most active group by ReliaQuest; DragonForce also remained prominent despite reported declines in some rankings. Professional, scientific, and technical services stayed the most targeted sector, and researchers noted a broader shift toward data-only extortion and continued pressure on organizations through public leak-site exposure. Researchers also highlighted technical changes in attacker tradecraft rather than a wholesale change in ransomware operations. The quarter saw increased use of AI and LLMs by threat actors, including analysis of exfiltrated databases and more tailored extortion messaging, alongside continued exploitation of high-impact vulnerabilities such as CVE-2026-50751, CVE-2026-48027, CVE-2026-46817, and CVE-2026-35273. ReliaQuest identified Deadlock as a notable re-emerging threat after 11 months of silence, using blockchain-hosted command-and-control through a Polygon smart contract and a BYOVD technique to terminate EDR tools via CVE-2024-51324. The reports say supply-chain compromise, remote access abuse, identity attacks, lateral movement, and defense evasion remain central to ransomware operations even as payment rates decline.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.