Skip to content

DragonForce

DragonForce is a ransomware and cyber-extortion operation associated with a Malaysia-based group that evolved from pro-Palestinian hacktivism into a financially motivated, affiliate-oriented ransomware ecosystem.

Profile source: Mallory opens in a new tab

DragonForce

Family profile

DragonForce is a ransomware and cyber-extortion operation associated with a Malaysia-based group that evolved from pro-Palestinian hacktivism into a financially motivated, affiliate-oriented ransomware ecosystem. It has targeted Israeli organizations and victims globally, with substantial reported activity against organizations in the United States and North America. The operation adopted a ransomware-cartel model in 2025, enabling affiliates to operate branded variants using shared infrastructure.

DragonForce employs double extortion: operators encrypt victim systems, exfiltrate data, and pressure victims through leak-site postings, time-limited publication deadlines, and potential publication of stolen material and negotiation records. Technical analysis assesses its Windows locker as a modified derivative of the leaked 2022 LockBit builder. It uses ChaCha20 encryption, can encrypt local and network-accessible resources, enumerates drives and network shares, terminates selected processes and services, impairs recovery through shadow-copy discovery, and creates ransom notes after encryption. The locker includes defense-evasion and anti-forensic functions, including dynamic API resolution, security-tool impairment options, event-log deletion options, and optional self-deletion.

In a 2025 intrusion against a US services organization, DragonForce operators maintained access for up to two months before ransomware deployment. They used Backdoor.Turn, a Go-based remote-access trojan that concealed command-and-control traffic through Microsoft Teams TURN relay infrastructure. Observed post-compromise activity included network scanning, browser credential theft, credential-based lateral movement, creation of accounts, firewall modification, data exfiltration, and ransomware encryption. The intrusion was assessed as likely beginning with exploitation of a vulnerability affecting an SQL-server environment. Separate incidents affecting Brazilian educational organizations involved deployment through AnyDesk after compromise of a user account.

DragonForce has been associated with attacks against industrial, manufacturing, services, education, and other sectors. Its public-facing extortion and propaganda activity has used leak-site and messaging-channel infrastructure, combining ideological messaging with profit-driven ransomware operations.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Scanning

Operational record

24
Indicators
1
YARA rules
2
Ransom notes
25
Negotiations
4
Leak sites
3 available

Credential Theft

  • Mimikatz

Discovery Enum

  • Advanced IP Scanner
  • PingCastle
  • SoftPerfect NetScan

Published indicators

Md5

22 total
  • 3a514e164db30acdb3063eb79a23aa4f
  • f0410358a0d9dbd0dff3113d9c744ca7
  • 99be93aa4c34b39fedcd37663c34511f
  • 2dd7cd2bf15eec7d62689435fca9c49c
  • 3c311cabe7de6a8c104f8f10541d392d
  • 12e22f588f6128cf1a042d1122556cd2
  • e4a4fc96188310b7b07e7c0525b5c0aa
  • 15634dc79981e7fba25fb8530cedb981
  • 8bcd83352bbd52ca7bda998a52dd0e5c
  • 6c755a742f2b2e5c1820f57d0338365f

Tox

1 total
  • 1C054B722BCBF41A918EF3C485712742088F5C3E81B2FDD91ADEA6BA55F4A856D90A65E99D20

Ip

1 total
  • 45.135.232.195

Recent claims

Reported operators

Threat actors

8 named in public reporting
DragonForce

DragonForce Ransomware is based on the LockBit builder from 2022, utilizing similar configurations and attack methods.

Scattered Spider

Criminal complaints against alleged Scattered Spider members and public reports reveal collaboration of the subclusters with ALPHV/Blackcat and Dragonforce.

Devman

Devman is a ransomware operator, believed to be located in Russia, who uses modified DragonForce code built on top of the leaked Conti source code.

GOLD HARVEST

When DragonForce emerged in August 2023, it offered a traditional RaaS scheme. On March 19, 2025, the group announced a rebrand as a ‘cartel’ to expand its reach, hoping to emulate the success of LockBit and other mature ransomware-as-a-service (RaaS) groups.

ShinyHunters

DragonForce posted 101 victims in Q1 2026 (an increase of 29% compared to Q4 2025), with a steep climb from 10 victims in January to 35 in February and 56 in March.

DragonForce Malaysia

“DragonForce ransomware was first identified in August 2023… DragonForce has two ransomware variants - one based on LockBit Ransomware and another based on the Conti Ransomware variant.”

Water Tambanakua

“DragonForce ransomware was first identified in August 2023… DragonForce has two ransomware variants - one based on LockBit Ransomware and another based on the Conti Ransomware variant.”

LAPSUS$

The final phase involves deploying ransomware. Recently we have seen the group prefer the DragonForce variant, particularly targeting virtualised environments.

Exploited software

Vulnerabilities linked to DragonForce

10 CVEs

MITRE ATT&CK

DragonForce in ATT&CK

44 distinct techniques

Reporting

Research mentioning DragonForce

Aug 26
Zdnet Zero Day

July was the worst month for ransomware victim claims in 2026 - or was it? | ZDNET

Security reporting has documented LameHug as the first publicly known malware to integrate a large language model, marking an escalation in the use of generative AI within malicious tooling. The development indicates that AI can be incorporated into malware operations rather than being used solely to create phishing content or assist attackers outside the payload. Separately, ransomware victim listings reached 894 organizations in July 2026, according to NCC Group data cited by ZDNET, with industrial organizations comprising nearly one-third of listed victims. The reporting also identified the first documented fully agentic AI ransomware attack chain, attributed to JadePuffer, amid a surge led by groups including The Gentlemen and Qilin; however, organizations should treat leak-site claims cautiously because some actors, including the new CRPxO RaaS operation, may inflate or fabricate victim listings.

Jul 25
The Hacker News

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

Researchers say DevMan, also tracked as Funky Mantis, operated a centralized ransomware-as-a-service platform with a dedicated affiliate portal for payload generation, victim management, ransom negotiation, earnings tracking, and internal coordination. PRODAFT reported the group was active from late 2025 into early 2026, used an 80/20 affiliate revenue split, and claimed 184 victims, with the heaviest concentration in the United States across technology, healthcare, financial services, professional services, and government. The operation explicitly pursued hospitals, critical infrastructure, the public sector, and law enforcement, and advertised a separate encryptor for SCADA environments, underscoring its focus on high-impact targets. Technical reporting links DevMan’s malware to DragonForce/Conti lineage while showing the operation evolved beyond a simple variant. Earlier analysis described a DragonForce-based sample marked by the .DEVMAN extension, SMB share probing, rapid encryption, and a builder flaw that encrypted its own ransom notes; later reporting identified a Rust-based Devman Locker using ChaCha20-Poly1305, appending .devman21, dropping RESTORE_FILES.txt, mounting network shares, disabling defenses, deleting shadow copies and event logs, and inhibiting recovery. The latest portal version reportedly supports Windows, Linux, and ESXi lockers and includes features for privilege checks, lateral movement, and security-tool impairment, indicating a mature and centrally managed extortion operation.

Jul 23
Cyberveille

Funky Mantis (DevMan) : analyse complète d'un RaaS centralisé ciblant hôpitaux et infrastructures critiques | CyberVeille

Jul 22
Itpro

'Perimeter defences are prime targets': Security experts issue alert over Palo Alto GlobalProtect VPN exploitation | IT Pro

Arctic Wolf Labs reported multiple intrusions in which threat actors exploited CVE-2026-0257 to gain initial access to victim networks and then quickly deployed Qilin ransomware. The incidents, observed across separate organizations, followed a consistent pattern in which perimeter compromise was followed by rapid movement toward broad encryption activity. The reporting indicates the attacks were distinct events but shared the same intrusion chain, linking exploitation of CVE-2026-0257 directly to domain-wide ransomware deployment. Arctic Wolf attributed the post-compromise activity to Qilin operations, highlighting the vulnerability as a recurring entry point in recent ransomware incidents.

Jul 22
Belgium Ccb News

Threat Intelligence Report: Qilin (Agenda) Ransomware | CCB Belgium

Qilin ransomware has emerged as one of the most active cybercrime threats, with NCC Group identifying it as the most prolific ransomware group for the fifth consecutive quarter as global ransomware incidents climbed to 2,229 in Q2 2026. The group, also tracked as Agenda or Qilin Locker, operates a double-extortion RaaS model and has concentrated on high-GDP Western countries while reportedly avoiding CIS member states. Manufacturing and other industrial sectors have been hit hardest, alongside business services, technology, healthcare, and finance, with North America remaining the most affected region and Belgium reporting at least 15 alleged Qilin compromises that disrupted operations and exposed sensitive corporate data.

Jul 22
Itsecurityguru

Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns - IT Security Guru

Jul 21
Scworld

Qilin exploits Palo Alto Networks GlobalProtect VPN firewalls | news | SC Media

Jul 21
Cyber Security News

Qilin Ransomware Claims 1,358 Victims as Global Attacks Reach New Record

Ransomware and cyber-extortion activity rose again in Q2 2026, with industry reporting showing more than 2,250 publicly named victims across roughly 90 active groups and nearly 100 countries. GuidePoint Security’s GRIT report counted 2,279 victims, up 7% from the prior quarter and 43% year over year, while ReliaQuest recorded 2,252 victims and found the United States accounted for about 49% of observed activity. Qilin remained a leading force in one dataset for a fifth straight quarter, while The Gentlemen surged into the top tier and was ranked the most active group by ReliaQuest; DragonForce also remained prominent despite reported declines in some rankings. Professional, scientific, and technical services stayed the most targeted sector, and researchers noted a broader shift toward data-only extortion and continued pressure on organizations through public leak-site exposure. Researchers also highlighted technical changes in attacker tradecraft rather than a wholesale change in ransomware operations. The quarter saw increased use of AI and LLMs by threat actors, including analysis of exfiltrated databases and more tailored extortion messaging, alongside continued exploitation of high-impact vulnerabilities such as CVE-2026-50751, CVE-2026-48027, CVE-2026-46817, and CVE-2026-35273. ReliaQuest identified Deadlock as a notable re-emerging threat after 11 months of silence, using blockchain-hosted command-and-control through a Polygon smart contract and a BYOVD technique to terminate EDR tools via CVE-2024-51324. The reports say supply-chain compromise, remote access abuse, identity attacks, lateral movement, and defense evasion remain central to ransomware operations even as payment rates decline.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.