DragonForce is a ransomware family and broader ransomware-as-a-service ecosystem associated with a threat group that evolved from earlier hacktivist activity into financially motivated cyber extortion. It has been described as operating a double-extortion model in which victims face both file encryption and threats to publish stolen data through leak infrastructure and public negotiation channels. By 2025, DragonForce had also adopted a cartel-style operating model that allowed affiliates to build and run their own branded variants on shared infrastructure, contributing to its prominence across North America and other regions.
Technical analysis indicates that DragonForce ransomware is closely derived from the leaked 2022 LockBit builder and retains similar configuration structure, execution flow, and operational features. Observed samples use ChaCha20 encryption, dynamically resolve APIs, enumerate local drives and network shares, terminate processes and services that may interfere with encryption, and inhibit recovery options including shadow-copy-related mechanisms. The malware can rename encrypted files, drop ransom notes, alter desktop wallpaper, and encrypt data on both local and network-accessible resources. Reported configuration and runtime behavior also support anti-forensics and defense-evasion actions such as event log deletion, self-deletion, and security-tool impairment.
DragonForce operations have been linked to sophisticated post-compromise tradecraft. In documented intrusions, operators or associated access providers used compromised accounts, remote administration tools, exploitation of internet-facing systems, and session hijacking against edge infrastructure to gain entry. Post-exploitation activity has included privilege escalation, creation of rogue accounts, persistence through legitimate remote-management software, credential theft, network scanning, lateral movement with administrative tooling, and data exfiltration prior to encryption. In one notable intrusion, operators used a Go-based backdoor known as Backdoor.Turn to conceal command-and-control traffic within Microsoft Teams TURN relay traffic, alongside BYOVD-style evasion using a vulnerable driver.
DragonForce has been observed targeting organizations in the United States, Canada, Brazil, South Korea, Vietnam, Israel, and elsewhere, with repeated reporting on impacts to services, manufacturing, education, and other enterprise sectors. The group has also been characterized as supply-chain-aware in parts of its targeting. Public reporting consistently places DragonForce among the more active ransomware brands of 2025 and 2026, although victim-post volumes fluctuated over time as affiliates shifted among competing ransomware programs.
DragonForce is also relevant as malware lineage: other ransomware operations and affiliate-led projects have been assessed as borrowing from or inheriting DragonForce code. Overall, DragonForce represents both a specific Windows ransomware family and a mature extortion platform combining encryption, data theft, affiliate operations, and advanced intrusion tradecraft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attack chain begins with exploitation of the “CitrixBleed 2” vulnerability in Citrix NetScaler appliances... Huntress assesses with high confidence that the activity is the work of an initial access broker (IAB) weaponising CVE-2025-5777... A pre-auth memory leak that defeats MFA CVE-2025-5777, dubbed CitrixBleed 2... is a pre-authentication memory-overread affecting NetScaler ADC and Gateway when configured as a Gateway or AAA virtual server. | ...in its most advanced form, ends in DragonForce ransomware... In the most progressed case, the operator used PsExec, Impacket-based tooling and Mimikatz for lateral movement and credential access before deploying a DragonForce ransomware binary...
DragonForce ransomware is an advanced and competitive ransomware-as-a-service (RaaS) brand that first emerged in mid-2023.
DragonForce ransomware is an advanced and competitive ransomware-as-a-service (RaaS) brand that first emerged in mid-2023.
DragonForce ransomware is an advanced and competitive ransomware-as-a-service (RaaS) brand that first emerged in mid-2023.
“DragonForce ransomware was first identified in August 2023… DragonForce has two ransomware variants - one based on LockBit Ransomware and another based on the Conti Ransomware variant.”
“DragonForce ransomware was first identified in August 2023… DragonForce has two ransomware variants - one based on LockBit Ransomware and another based on the Conti Ransomware variant.”
“DragonForce ransomware was first identified in August 2023… DragonForce has two ransomware variants - one based on LockBit Ransomware and another based on the Conti Ransomware variant.”
“DragonForce ransomware was first identified in August 2023… DragonForce has two ransomware variants - one based on LockBit Ransomware and another based on the Conti Ransomware variant.”
“DragonForce ransomware was first identified in August 2023… DragonForce has two ransomware variants - one based on LockBit Ransomware and another based on the Conti Ransomware variant.”
Fortinet FortiOS CVE-2024-55591, a zero-day authentication bypass vulnerability disclosed in January 2025, had the highest count of ransomware groups attached to it as the year closed, with six named ransomware families (DragonForce, Hunters International, NightSpire, Qilin, RansomHub, and SuperBlack)...
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DragonForce Ransomware is based on the LockBit builder from 2022, utilizing similar configurations and attack methods.
Criminal complaints against alleged Scattered Spider members and public reports reveal collaboration of the subclusters with ALPHV/Blackcat and Dragonforce.
Devman is a ransomware operator, believed to be located in Russia, who uses modified DragonForce code built on top of the leaked Conti source code.
When DragonForce emerged in August 2023, it offered a traditional RaaS scheme. On March 19, 2025, the group announced a rebrand as a ‘cartel’ to expand its reach, hoping to emulate the success of LockBit and other mature ransomware-as-a-service (RaaS) groups.
DragonForce posted 101 victims in Q1 2026 (an increase of 29% compared to Q4 2025), with a steep climb from 10 victims in January to 35 in February and 56 in March.
“DragonForce ransomware was first identified in August 2023… DragonForce has two ransomware variants - one based on LockBit Ransomware and another based on the Conti Ransomware variant.”
32 distinct techniques documented for this family, organized by ATT&CK tactic.
The DragonForce ransomware group initially infiltrated the victim system network via a remote desktop server and attempted persistent logins using valid domain accounts (Domain Accounts, T1078.002).
Notable Behaviour: - Initial Access via public-facing RDP (TA0001/T1133)
When the “schedule_job” field in the Config information is enabled, the process of registering a job that runs with SYSTEM privileges to the scheduler is performed.
The DragonForce ransomware group initially infiltrated the victim system network via a remote desktop server and attempted persistent logins using valid domain accounts (Domain Accounts, T1078.002).
When the “schedule_job” field in the Config information is enabled, the process of registering a job that runs with SYSTEM privileges to the scheduler is performed.
DragonForce ransomware uses two methods to terminate predefined processes. The first method utilizes the BYOVD (Bring Your Own Vulnerable Driver) technique, exploiting vulnerable drivers...
All strings used by DragonForce ransomware are obfuscated and decrypted using a custom algorithm.
...some samples... were found to perform API resolving based on the MurMurHash2 algorithm to dynamically load the API.
Appendix C. MITRE ATT&CK ... (T1070.001) Clear Windows Event Logs
In the most progressed case, the operator used PsExec, Impacket-based tooling and Mimikatz for lateral movement and credential access before deploying a DragonForce ransomware binary
Subsequently, the attacker used Mimikatz to dump credential information (LSASS Memory, T1003.001) and collected Active Directory configuration...
one that begins with exploitation of the “CitrixBleed 2” vulnerability in Citrix NetScaler appliances... Huntress assesses with high confidence that the activity is the work of an initial access broker (IAB) weaponising CVE-2025-5777 to gain footholds in Citrix environments
...collected Active Directory configuration (Domain Trust Discovery, T1482) and network information (System Network Configuration Discovery, T1016) via ADFind and netscanold.exe.
Appendix C. MITRE ATT&CK ... (T1082) System Information Discovery
Before performing encryption, a directory traversal is conducted to identify files to be encrypted.
In the most progressed case, the operator used PsExec, Impacket-based tooling and Mimikatz for lateral movement and credential access
За десять месяцев, с апреля 2025-го по февраль 2026-го, Devman атаковал 187 организаций... Выкупы он требовал в диапазоне от 60 тысяч до 91 миллиона долларов.
65 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
142 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operator with strong US focus and apparent interest in cross-border manufacturing and construction supply chains, creating both direct-targeting and lateral-access risk.
Ransomware operator focused on US-heavy activity with apparent emphasis on manufacturing and construction supply chains and cross-border lateral-access opportunities.
Ransomware family stated to have used leaked Conti source code as a basis.
DragonForce is mentioned only as part of a separate referenced ransomware attack headline.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.