Skip to content

DragonForce

DragonForce is a ransomware family and ransomware-as-a-service operation active since at least 2025 that has been associated with double-extortion intrusions against organizations worldwide.

Profile source: Mallory opens in a new tab

DragonForce

Family profile

DragonForce is a ransomware family and ransomware-as-a-service operation active since at least 2025 that has been associated with double-extortion intrusions against organizations worldwide. It has targeted sectors including manufacturing, business services, education, healthcare, retail, and industrial organizations, and has also been linked in some reporting to activity involving Scattered Spider. In 2025 the operation rebranded itself as a "ransomware cartel," allowing affiliates to build and run their own branded variants on shared DragonForce infrastructure, reflecting a broader affiliate-driven operating model.

DragonForce intrusions have been observed following compromise of valid accounts, exploitation of internet-facing systems and edge appliances, and abuse of remote-access software. Reported cases include deployment after compromise of Citrix NetScaler environments via session hijacking tied to CVE-2025-5777, as well as incidents where attackers installed remote-management tools such as AnyDesk to establish access before ransomware execution. In some environments, operators moved from initial access to ransomware deployment in under an hour, while other intrusions involved long dwell time and extensive hands-on-keyboard activity.

The malware and its operators have demonstrated mature post-compromise tradecraft. Observed behaviors include privilege escalation, creation of rogue user accounts, modification of firewall and security settings, credential theft, lateral movement using administrative tooling, network reconnaissance and scanning, data exfiltration, and encryption of victim systems. DragonForce activity has also been associated with defense evasion techniques such as log clearing, disabling or impairing security controls, and bring-your-own-vulnerable-driver-style evasion. In one notable intrusion chain, operators used a Go-based backdoor known as Backdoor.Turn to conceal command-and-control traffic within legitimate Microsoft Teams TURN relay traffic, blending malicious communications with normal enterprise network activity.

DragonForce has been repeatedly identified among the more active ransomware brands in 2025 and 2026 victim-leak reporting. Its ecosystem appears to include affiliates and derivative operations, and some researchers have assessed malware lineage connections between DragonForce and later ransomware projects such as DevMan. The operation is notable for combining conventional ransomware objectives with increasingly sophisticated access, persistence, and evasion tradecraft.

Capabilities

  • Byovd
  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Privilege Escalation
  • Reconnaissance
  • Scanning
  • Session Hijacking

Operational record

24
Indicators
1
YARA rules
2
Ransom notes
25
Negotiations
3
Leak sites
3 available

Credential Theft

  • Mimikatz

Discovery Enum

  • Advanced IP Scanner
  • PingCastle
  • SoftPerfect NetScan

Published indicators

Md5

22 total
  • 3a514e164db30acdb3063eb79a23aa4f
  • f0410358a0d9dbd0dff3113d9c744ca7
  • 99be93aa4c34b39fedcd37663c34511f
  • 2dd7cd2bf15eec7d62689435fca9c49c
  • 3c311cabe7de6a8c104f8f10541d392d
  • 12e22f588f6128cf1a042d1122556cd2
  • e4a4fc96188310b7b07e7c0525b5c0aa
  • 15634dc79981e7fba25fb8530cedb981
  • 8bcd83352bbd52ca7bda998a52dd0e5c
  • 6c755a742f2b2e5c1820f57d0338365f

Tox

1 total
  • 1C054B722BCBF41A918EF3C485712742088F5C3E81B2FDD91ADEA6BA55F4A856D90A65E99D20

Ip

1 total
  • 45.135.232.195

Recent claims

Reported operators

Threat actors

8 named in public reporting
Scattered Spider

Criminal complaints against alleged Scattered Spider members and public reports reveal collaboration of the subclusters with ALPHV/Blackcat and Dragonforce.

Devman

Devman is a ransomware operator, believed to be located in Russia, who uses modified DragonForce code built on top of the leaked Conti source code.

DragonForce

The DragonForce Ransomware Group, first detected in December 2023, developed its own ransomware based on LockBit 3.0 (Black) and Conti Ransomware code.

GOLD HARVEST

When DragonForce emerged in August 2023, it offered a traditional RaaS scheme. On March 19, 2025, the group announced a rebrand as a ‘cartel’ to expand its reach, hoping to emulate the success of LockBit and other mature ransomware-as-a-service (RaaS) groups.

ShinyHunters

DragonForce posted 101 victims in Q1 2026 (an increase of 29% compared to Q4 2025), with a steep climb from 10 victims in January to 35 in February and 56 in March.

DragonForce Malaysia

“DragonForce ransomware was first identified in August 2023… DragonForce has two ransomware variants - one based on LockBit Ransomware and another based on the Conti Ransomware variant.”

Water Tambanakua

“DragonForce ransomware was first identified in August 2023… DragonForce has two ransomware variants - one based on LockBit Ransomware and another based on the Conti Ransomware variant.”

LAPSUS$

The final phase involves deploying ransomware. Recently we have seen the group prefer the DragonForce variant, particularly targeting virtualised environments.

Exploited software

Vulnerabilities linked to DragonForce

10 CVEs

MITRE ATT&CK

DragonForce in ATT&CK

44 distinct techniques

Reporting

Research mentioning DragonForce

Jul 25
The Hacker News

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

Researchers say DevMan, also tracked as Funky Mantis, operated a centralized ransomware-as-a-service platform with a dedicated affiliate portal for payload generation, victim management, ransom negotiation, earnings tracking, and internal coordination. PRODAFT reported the group was active from late 2025 into early 2026, used an 80/20 affiliate revenue split, and claimed 184 victims, with the heaviest concentration in the United States across technology, healthcare, financial services, professional services, and government. The operation explicitly pursued hospitals, critical infrastructure, the public sector, and law enforcement, and advertised a separate encryptor for SCADA environments, underscoring its focus on high-impact targets. Technical reporting links DevMan’s malware to DragonForce/Conti lineage while showing the operation evolved beyond a simple variant. Earlier analysis described a DragonForce-based sample marked by the .DEVMAN extension, SMB share probing, rapid encryption, and a builder flaw that encrypted its own ransom notes; later reporting identified a Rust-based Devman Locker using ChaCha20-Poly1305, appending .devman21, dropping RESTORE_FILES.txt, mounting network shares, disabling defenses, deleting shadow copies and event logs, and inhibiting recovery. The latest portal version reportedly supports Windows, Linux, and ESXi lockers and includes features for privilege checks, lateral movement, and security-tool impairment, indicating a mature and centrally managed extortion operation.

Jul 23
Cyberveille

Funky Mantis (DevMan) : analyse complète d'un RaaS centralisé ciblant hôpitaux et infrastructures critiques | CyberVeille

Jul 22
Itpro

'Perimeter defences are prime targets': Security experts issue alert over Palo Alto GlobalProtect VPN exploitation | IT Pro

Arctic Wolf Labs reported multiple intrusions in which threat actors exploited CVE-2026-0257 to gain initial access to victim networks and then quickly deployed Qilin ransomware. The incidents, observed across separate organizations, followed a consistent pattern in which perimeter compromise was followed by rapid movement toward broad encryption activity. The reporting indicates the attacks were distinct events but shared the same intrusion chain, linking exploitation of CVE-2026-0257 directly to domain-wide ransomware deployment. Arctic Wolf attributed the post-compromise activity to Qilin operations, highlighting the vulnerability as a recurring entry point in recent ransomware incidents.

Jul 22
Belgium Ccb News

Threat Intelligence Report: Qilin (Agenda) Ransomware | CCB Belgium

Qilin ransomware has emerged as one of the most active cybercrime threats, with NCC Group identifying it as the most prolific ransomware group for the fifth consecutive quarter as global ransomware incidents climbed to 2,229 in Q2 2026. The group, also tracked as Agenda or Qilin Locker, operates a double-extortion RaaS model and has concentrated on high-GDP Western countries while reportedly avoiding CIS member states. Manufacturing and other industrial sectors have been hit hardest, alongside business services, technology, healthcare, and finance, with North America remaining the most affected region and Belgium reporting at least 15 alleged Qilin compromises that disrupted operations and exposed sensitive corporate data.

Jul 22
Itsecurityguru

Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns - IT Security Guru

Jul 21
Scworld

Qilin exploits Palo Alto Networks GlobalProtect VPN firewalls | news | SC Media

Jul 21
Cyber Security News

Qilin Ransomware Claims 1,358 Victims as Global Attacks Reach New Record

Ransomware and cyber-extortion activity rose again in Q2 2026, with industry reporting showing more than 2,250 publicly named victims across roughly 90 active groups and nearly 100 countries. GuidePoint Security’s GRIT report counted 2,279 victims, up 7% from the prior quarter and 43% year over year, while ReliaQuest recorded 2,252 victims and found the United States accounted for about 49% of observed activity. Qilin remained a leading force in one dataset for a fifth straight quarter, while The Gentlemen surged into the top tier and was ranked the most active group by ReliaQuest; DragonForce also remained prominent despite reported declines in some rankings. Professional, scientific, and technical services stayed the most targeted sector, and researchers noted a broader shift toward data-only extortion and continued pressure on organizations through public leak-site exposure. Researchers also highlighted technical changes in attacker tradecraft rather than a wholesale change in ransomware operations. The quarter saw increased use of AI and LLMs by threat actors, including analysis of exfiltrated databases and more tailored extortion messaging, alongside continued exploitation of high-impact vulnerabilities such as CVE-2026-50751, CVE-2026-48027, CVE-2026-46817, and CVE-2026-35273. ReliaQuest identified Deadlock as a notable re-emerging threat after 11 months of silence, using blockchain-hosted command-and-control through a Polygon smart contract and a BYOVD technique to terminate EDR tools via CVE-2024-51324. The reports say supply-chain compromise, remote access abuse, identity attacks, lateral movement, and defense evasion remain central to ransomware operations even as payment rates decline.

Jul 21
Security Affairs

Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.