Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Ransomware1 malware family

slippery_scorpius

Also known asslippery_scorpius

Slippery Scorpius is Unit 42’s name for the group behind DragonForce ransomware. The group was first detected in November 2023 and became more prominent in 2024. DragonForce is described as a ransomware-as-a-service program, and Slippery Scorpius is associated with double-extortion activity. Reported behavior includes extorting victims directly through phone calls and leaking recorded audio of those conversations. Unit 42 also reported that since at least April 2025, Muddled Libra (also known as Scattered Spider and UNC3944) partnered with the DragonForce RaaS program operated by Slippery Scorpius to extort victims, including at least one case involving more than 100 GB of data exfiltration followed by DragonForce ransomware deployment. No additional aliases for Slippery Scorpius beyond DragonForce are directly provided in the content.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.

slippery_scorpius | Mallory