DragonForce is a ransomware family and ransomware-as-a-service operation that emerged in mid-to-late 2023. Early payloads reused leaked LockBit 3.0 tooling, while later variants incorporated Conti-derived code. It targets Windows, Linux, and VMware ESXi environments and uses double extortion, combining file encryption with operational data theft and threats of public disclosure. In March 2025, the operation adopted a ransomware-cartel model offering white-label infrastructure, customizable payloads, negotiation services, and data-leak facilities to affiliates operating under their own brands. Targets span manufacturing, construction, technology, healthcare, retail, and other public- and private-sector organizations internationally.
Analyzed Windows payloads decode configuration and strings at runtime, collect host and account information, terminate selected security, backup, database, and business processes, and delete Volume Shadow Copies to inhibit recovery. They identify local drives and network-accessible SMB shares, including by inspecting existing ARP-cache entries rather than actively scanning the subnet. Parallel encryption workers process local and network files using per-file ChaCha20 encryption material protected by an embedded 4096-bit RSA public key. Configurable full and partial encryption, file exclusions, randomized filenames, encrypted activity logging, ransom notes, and desktop customization support deployment and extortion. Data exfiltration is established at the campaign level but was not demonstrated within the analyzed Windows encryptor execution.
DragonForce campaigns use compromised credentials, phishing, exploitation of public-facing applications, and abuse of legitimate remote-management tools. Exploitation of SimpleHelp vulnerabilities enabled compromise of a managed service provider and ransomware deployment across downstream customer environments. Associated intrusion activity includes credential harvesting, reconnaissance, lateral movement, and security-control tampering. DragonForce actors have also used vulnerable drivers to disable endpoint defenses. Scattered Spider and Storm-2570 have deployed DragonForce ransomware. The operation has additionally deployed custom backdoors using Microsoft Teams TURN relays and fallback MQTT communications, with scheduled-task persistence, DLL sideloading, encrypted payload delivery, and in-memory execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
DragonForce affiliates employ a range of initial access vectors to infiltrate target environments. These commonly include: ... Exploitation of publicly known vulnerabilities, notably Log4Shell (CVE-2021-44228).
CVE-2024-57728 (CVSS 7.2): An arbitrary file upload vulnerability enabling attackers to introduce malicious payloads into the environment.
Notably, the group exploits multiple vulnerabilities to conduct attacks. These vulnerabilities include CVE-2024-21412, CVE-2024-21887, and CVE-2024-21893.
Notably, the group exploits multiple vulnerabilities to conduct attacks. These vulnerabilities include CVE-2024-21412, CVE-2024-21887, and CVE-2024-21893.
CVE-2024-57727 (CVSS 7.5): A set of path traversal flaws that allow attackers to navigate directories and access restricted files.
Notably, the group exploits multiple vulnerabilities to conduct attacks. These vulnerabilities include CVE-2024-21412, CVE-2024-21887, and CVE-2024-21893.
CVE-2024-57726 (CVSS 9.9): A privilege escalation flaw that grants elevated permissions once initial access is gained.
Abusing a legitimate-but-vulnerable driver K7RKScan.sys (CVE-2025-1055) as part of a BYOVD attack to disable security software. The same driver was previously exploited by DragonForce ransomware actors. | "Abusing a legitimate-but-vulnerable driver K7RKScan.sys (CVE-2025-1055) as part of a BYOVD attack to disable security software. The same driver was previously exploited by DragonForce ransomware actors."
The attack chain begins with exploitation of the “CitrixBleed 2” vulnerability in Citrix NetScaler appliances... Huntress assesses with high confidence that the activity is the work of an initial access broker (IAB) weaponising CVE-2025-5777... A pre-auth memory leak that defeats MFA CVE-2025-5777, dubbed CitrixBleed 2... is a pre-authentication memory-overread affecting NetScaler ADC and Gateway when configured as a Gateway or AAA virtual server. | ...in its most advanced form, ends in DragonForce ransomware... In the most progressed case, the operator used PsExec, Impacket-based tooling and Mimikatz for lateral movement and credential access before deploying a DragonForce ransomware binary...
“DragonForce ransomware was first identified in August 2023… DragonForce has two ransomware variants - one based on LockBit Ransomware and another based on the Conti Ransomware variant.”
Fortinet FortiOS CVE-2024-55591, a zero-day authentication bypass vulnerability disclosed in January 2025, had the highest count of ransomware groups attached to it as the year closed, with six named ransomware families (DragonForce, Hunters International, NightSpire, Qilin, RansomHub, and SuperBlack)...
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
While DragonForce took credit for the extortion and data leak phase, growing evidence suggests that another group—Scattered Spider—may have played a foundational role in enabling those attacks.
DragonForce exploited a set of vulnerabilities in SimpleHelp, a popular Remote Monitoring and Management (RMM) tool, to breach an MSP and deploy ransomware across multiple client environments.
Devman was observed launching a new RaaS platform based on modified code from the "DragonForce" ransomware family.
Analysts from Microsoft identified a consistent pattern after access was gained, even when attacks ended with Qilin, DragonForce, Anubis or BERT ransomware.
The 2025 wave of UK retail attacks against Marks & Spencer, Co-op, and Harrods deployed DragonForce ransomware.
When DragonForce emerged in August 2023, it offered a traditional RaaS scheme. On March 19, 2025, the group announced a rebrand as a ‘cartel’ to expand its reach, hoping to emulate the success of LockBit and other mature ransomware-as-a-service (RaaS) groups.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
“[The sample] initializes COM and WMI, queries the Win32_ShadowCopy class, and uses each returned shadow-copy identifier to construct and execute a WMIC deletion command.”
DragonForce obfuscates its payload by packing or encrypting parts of the code.
In the most progressed case, the operator used PsExec, Impacket-based tooling and Mimikatz for lateral movement and credential access before deploying a DragonForce ransomware binary
one that begins with exploitation of the “CitrixBleed 2” vulnerability in Citrix NetScaler appliances... Huntress assesses with high confidence that the activity is the work of an initial access broker (IAB) weaponising CVE-2025-5777 to gain footholds in Citrix environments
“Before target processing, the sample retrieves the current user SID and resolves account information.”
“Background monitoring workers repeatedly enumerate running processes, compare names against this list, and attempt to terminate matches.”
DragonForce gathers system information such as the operating system version, architecture, and installed applications.
The malware employs intermittent encryption and evasion techniques to bypass EDR and anti-ransomware defenses.
76 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
170 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a participant in a ransomware alliance with LockBit and Qilin intended to share tools and infrastructure and improve attack effectiveness. The article provides no specific details about its payload capabilities or victims.
Mentioned in a background account of a ransomware operator's website being defaced. The reference provides no technical details about the ransomware.
Mentioned as a historical comparison: DragonForce ransomware actors previously exploited the same vulnerable K7RKScan.sys driver used in the reported Warlock campaign. The article does not describe DragonForce deployment in the current intrusions.
A ransomware-as-a-service operation whose observed tooling includes custom persistent backdoors. The backdoors use legitimate Microsoft Teams TURN servers and MQTT as redundant C2 channels, execute payloads in memory, use DLL sideloading and scheduled-task persistence, encrypt payloads, and encrypt their active memory before sleeping to hinder detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.