DragonForce has expanded from a ransomware operation identified in 2023 into a ransomware-as-a-service business and a self-described cartel announced in March 2025. The group claimed more than 120 victims over the year preceding Bitdefender’s June 2025 report and offers affiliates 80% of profits, infrastructure, and operational services while retaining control over partner resources. Its affiliates steal data and encrypt Windows, Linux, and ESXi environments, targeting disruption-sensitive sectors including manufacturing, healthcare, retail, and transportation across North America, Europe, and Asia. A separate February 2025 report identified Saudi Arabia as a target, while Bitdefender reported Scattered Spider deploying DragonForce ransomware.
Reported attack methods include phishing, credential abuse, vulnerability exploitation, living-off-the-land techniques, encrypted command-and-control tunneling, and disabling endpoint defenses. DragonForce reportedly uses ransomware derived from LockBit and Conti. Its cartel expansion has coincided with rivalries and disputed alliances: reports describe DragonForce defacing Mamona’s leak site, a contested partnership with RansomHub, and operational turmoil surrounding RansomHub’s April 2025 disappearance. DragonForce’s alleged hacktivist origins, relationship to DragonForce Malaysia, state ties, and involvement in a LockBit compromise remain unconfirmed. Defensive priorities include phishing-resistant authentication, rapid remediation of exposed vulnerabilities, monitoring for credential misuse and endpoint-security tampering, and tested, isolated backups across server and virtualization environments.

TTPs, infrastructure, and targeting history in one profile.
17 events from the most recent confirmed update back to the earliest known activity.
LockBit suffered a compromise in May 2025. Bitdefender discussed possible DragonForce responsibility only as an unconfirmed hypothesis.
In early May, DragonForce removed CAPTCHA verification from its leak site and placed the site under a global update model.
DragonForce announced a temporary pause in accepting new collaborators, citing recent events.
Koley published a screenshot purporting to show that DragonForce's data leak site had been compromised and defaced. The displayed message alleged internal betrayal, but the compromise was not independently established in the report.
RansomHub spokesperson koley resurfaced, claiming that a state-sponsored cyberattack had disrupted the operation and alleging betrayal by an insider. The report does not establish those allegations.
DragonForce issued a public invitation for RansomHub to join its infrastructure following RansomHub's disappearance. Some observers interpreted the announcement as a taunt.
RansomHub's data leak site went offline, and communications with affiliates reportedly stopped.
DragonForce defaced Mamona's data leak site after Mamona's infrastructure was published online. Bitdefender assessed the action as a likely effort to undermine an emerging ransomware-as-a-service competitor.
DragonForce announced a cartel model offering partners infrastructure and operational services. The arrangement gives partners 80% of profits while DragonForce retains 20%.
DragonForce demanded $7 million in a documented negotiation with an unnamed victim. The report describes the group researching victim revenues to determine ransom demands.
During summer 2024, DragonForce adopted a ransomware-as-a-service model and deployed a Conti-derived ransomware variant, following its earlier use of LockBit-derived ransomware.
DragonForce launched its DragonLeaks dark-web portal to publish stolen data, shame victims, and support ransom negotiations.
DragonForce emerged as a ransomware operation and was identified by researchers in fall 2023. Its early ransomware shared characteristics with LockBit 3.0; a connection to DragonForce Malaysia was not established.
A disgruntled developer leaked the LockBit 3.0 ransomware builder, according to the report. DragonForce later used this builder for its initial ransomware.
DragonForce abused the SimpleHelp remote monitoring and management tool in campaigns against managed service providers to establish remote control and move laterally through victim networks.
Bitdefender described Scattered Spider impersonating IT support personnel to obtain initial access before deploying DragonForce ransomware and other malicious tools.
Following RansomHub's outage, DragonForce claimed a partnership and displayed links to a page labeled "RansomHub R.I.P. (03.03.2025)." Its continuing invitation for RansomHub to join raised questions about whether any partnership was voluntary.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
darkatlas.io
Open sourcebitdefender.com
Open sourceresecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.