DragonForce is a ransomware and extortion threat actor widely tracked as a ransomware-as-a-service operation and sometimes branding itself as a broader ransomware cartel. High-confidence reporting also links the name to earlier Malaysia-based hacktivist activity, including pro-Palestinian operations against Israeli and Indian targets, indicating that the DragonForce brand has been associated with both ideological and financially motivated campaigns over time. The actor is also referred to as Slippery Scorpius. As a ransomware operation, DragonForce has been among the most active groups observed in 2026, with a particularly strong concentration of victims in the United States and additional activity across Europe and the Americas. Reported victims and sectoral analyses indicate targeting of business services, healthcare, manufacturing, technology, construction, financial services, and other commercial organizations. Multiple assessments characterize its targeting as supply-chain-aware rather than purely opportunistic. DragonForce operates a leak site and uses extortion pressure based on stolen data in addition to encryption. Reported tactics include dedicated victim pages, countdown-based pressure, publication of stolen data, and release of negotiation material when victims do not pay. The group has been described as using a double-extortion model and as supporting affiliates who receive a substantial share of ransom proceeds. Technical reporting attributes mature tradecraft to DragonForce intrusions. In one major 2025 intrusion against a US services firm, operators reportedly maintained access for up to two months before ransomware deployment. They used a Go-based remote access trojan known as Backdoor.Turn to conceal command-and-control traffic within Microsoft Teams TURN relay infrastructure, combined with multi-vector bring-your-own-vulnerable-driver evasion. Observed post-compromise actions included creation of user accounts, modification of firewall rules, weakening of security settings, internal network scanning, browser credential theft, credential-based lateral movement, data exfiltration, and eventual encryption. Malware analysis of DragonForce ransomware indicates code lineage or derivation from leaked builder ecosystems associated with LockBit and, separately, use of Conti-derived code as a basis in 2023. Reported functionality includes dynamic API resolution, ChaCha20-based file encryption, process and service termination, shadow-copy discovery, local-drive and network-share enumeration, privilege checks, anti-forensics options, and encryption of network-accessible resources. DragonForce intrusions have also been associated with tooling such as ThrottleBlood. Earlier DragonForce activity was tied to hacktivist campaigns using website targeting, vulnerability exploitation, reconnaissance through search-engine and internet-exposure discovery, and HTTP-flooding DDoS attacks. Those operations reportedly focused on Indian government and related entities in 2022 and on Israeli targets beginning in 2021. Overall, DragonForce represents a hybrid threat brand spanning hacktivist origins and a later high-tempo ransomware enterprise, with demonstrated capabilities in initial access, persistence, defense evasion, credential theft, lateral movement, exfiltration, and encryption-based extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 malware families attributed to this actor across reporting.
12 additional families tracked in Mallory.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
SimpleHelp RMM CVE-2024-57727 & CVE-2024-57728 DragonForce sophos.com
SimpleHelp RMM CVE-2024-57727 & CVE-2024-57728 DragonForce sophos.com
Researchers said the attackers used a new tool called Havoc Process Terminator to exploit a Huawei audio driver, tracked as HWAudioOs2Ec.sys. They also exploited three documented driver vulnerabilities CVE-2023-52271 in Topaz Antifraud, CVE-2025-61155 in Tower of Fantasy, and CVE-2025-1055 in K7 Security Anti-Malware.
The campaigns, uncovered in early 2025, leveraged a trio of flaws—CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728—to pivot from compromised RMM servers into victim networks with “minimal friction.”
Researchers said the attackers used a new tool called Havoc Process Terminator to exploit a Huawei audio driver, tracked as HWAudioOs2Ec.sys. They also exploited three documented driver vulnerabilities CVE-2023-52271 in Topaz Antifraud, CVE-2025-61155 in Tower of Fantasy, and CVE-2025-1055 in K7 Security Anti-Malware.
10 more CVEs tied to this actor tracked in Mallory.
106 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of the ransomware groups in incidents where Ransom Busters was observed contacting victims.
Listed among the most active ransomware groups in the reporting period discussed.
Referenced as another threat actor that used Microsoft Teams relay infrastructure for covert C2 traffic via Backdoor.Turn.
Conducting a ransomware attack resulting in a data breach against Vermont XCenter in Brazil.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.