DragonForce, also known as Dragon Force and Slippery Scorpius, is a financially motivated ransomware operation identified in 2023. It operates a ransomware-as-a-service platform and announced a ransomware cartel model in March 2025, allowing affiliates to use its infrastructure under their own branding. Its affiliate services include customizable ransomware, administrative and victim portals, negotiation support, workflow automation, stolen-data storage, and data-leak publishing. The cartel model offers affiliates 80% of ransom proceeds while the operators retain 20%. DevMan has operated as an affiliate of DragonForce as well as other ransomware programs. DragonForce targets organizations across multiple regions, including the United States, United Kingdom, Italy, Australia, France, and Brazil. Its targets include manufacturing, construction, technology, managed service providers, healthcare, retail, financial services, telecommunications, transportation, and public-sector organizations. It uses double extortion, combining system encryption with theft of sensitive information and threats to publish stolen data through its leak infrastructure. The operation has used ransomware derived from the leaked LockBit 3.0 builder and modified Conti code, with encryptors supporting Windows, Linux, and VMware ESXi environments. Its payloads provide configurable full and partial encryption. Intrusions involve phishing, compromised credentials, brute-force attacks against exposed remote-access services, and exploitation of known vulnerabilities. DragonForce exploited SimpleHelp vulnerabilities CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728 to compromise a managed service provider and reach downstream customer environments through legitimate remote-management infrastructure. That campaign included credential harvesting, reconnaissance, data exfiltration, and ransomware deployment. DragonForce operations use legitimate administration tools and remote services for execution, persistence, and lateral movement. Associated techniques include credential dumping, scheduled tasks, network and system discovery, encrypted command-and-control tunneling, log removal, security-tool interference, anti-analysis checks, and Bring Your Own Vulnerable Driver techniques. The group also engages in competition with other ransomware operations, including defacement of BlackLock and Mamona leak sites in March 2025. Its country of origin is not established, and a connection to the separate DragonForce Malaysia hacktivist collective has not been confirmed.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 malware families attributed to this actor across reporting.
13 additional families tracked in Mallory.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
CVE-2024-57727 (CVSS 7.5): A set of path traversal flaws that allow attackers to navigate directories and access restricted files.
CVE-2024-57728 (CVSS 7.2): An arbitrary file upload vulnerability enabling attackers to introduce malicious payloads into the environment.
The attackers abused the legitimate but vulnerable K7RKScan.sys driver (CVE-2025-1055) in a Bring Your Own Vulnerable Driver attack to disable security software. The same driver had previously been abused by DragonForce ransomware actors.
CVE-2024-57726 (CVSS 9.9): A privilege escalation flaw that grants elevated permissions once initial access is gained.
Researchers said the attackers used a new tool called Havoc Process Terminator to exploit a Huawei audio driver, tracked as HWAudioOs2Ec.sys. They also exploited three documented driver vulnerabilities CVE-2023-52271 in Topaz Antifraud, CVE-2025-61155 in Tower of Fantasy, and CVE-2025-1055 in K7 Security Anti-Malware.
10 more CVEs tied to this actor tracked in Mallory.
138 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a participant in a ransomware alliance with LockBit and Qilin intended to improve attack effectiveness through shared tools and infrastructure. No involvement in the arrest or investigated attacks is specified.
Identified as an active ransomware operator in underground reporting used to assess threats to healthcare organizations.
Reportedly conducted a ransomware attack against Petrosul, a Brazilian fuel-storage terminal operator. The report dates the breach to October 7, 2026, at 23:10 UTC and its discovery to 23:29 UTC. It provides no details about initial access, the ransomware family, or the extent of the data breach.
Reportedly attacked French construction-products supplier RÉSO, stealing 676 GB of confidential customer, partner, and employee information and locking its network, including nearly 8 TB of Veeam backups. The report states that the company did not reach an agreement with the attackers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.