DragonForce is a ransomware threat actor active by at least 2026 and tracked among major ransomware groups. It operates a leak-site-based extortion model associated with public disclosure of victim organizations, indicating involvement in ransomware-driven extortion activity. Reported victimology places its operations across multiple regions and industries worldwide, with notable impact on critical infrastructure-related sectors such as manufacturing, healthcare, and finance. DragonForce is commonly referenced under the standardized name DragonForce; the supplied alias "dragonfoece" appears to be a misspelling or variant rendering of that name. High-confidence public facts in the available material support classification as a ransomware actor, but do not provide sufficient corroborated detail here on its origin, specific intrusion tradecraft, affiliate structure, or distinct sub-groups.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.