Skip to content

DragonForce

Ransomware Group1 claimLast activity:

Overview

DragonForce is a financially motivated ransomware-as-a-service brand first observed in August 2023. Sophos Counter Threat Unit reported that it began as a conventional affiliate service and announced a new self-described cartel model in March 2025. The model is better understood as distributed or white-label affiliate branding: partners can use DragonForce infrastructure and ransomware while operating under their own names. This profile concerns the ransomware operation; the reviewed sources do not establish a relationship with the separate hacktivist name DragonForce Malaysia.

Activity and targeting

DragonForce has supported attacks across sectors and regions, including high-impact incidents affecting traditional IT and virtualized infrastructure. Sophos reported that the brand gained visibility during 2025 retail-sector intrusions and competed aggressively for affiliates after disruption or instability at other ransomware services. Those public attributions and DragonForce’s own victim claims require incident-specific corroboration; use of its ransomware can indicate an affiliate rather than direct action by the core operators.

The operation also targeted rival ransomware brands and promoted purported alliances or takeovers in underground forums. Sophos observed apparent defacements of BlackLock and Mamona sites and contested messaging around RansomHub. These events show competition and recruitment activity, but they do not prove that every advertised coalition or takeover produced a stable operational relationship.

Methods and operational characteristics

DragonForce provides affiliates with ransomware, leak and negotiation infrastructure and operational support. Sophos reported emphasis on credential theft, Active Directory abuse, data exfiltration and encryption of both conventional systems and VMware ESXi environments. The service’s distributed model permits affiliates to bring their own access methods, malware and branding, which increases variation between incidents.

In a separate Sophos MDR investigation, an actor compromised a managed service provider’s SimpleHelp remote-management environment, inventoried customer systems and deployed DragonForce ransomware across multiple endpoints. Sophos assessed with medium confidence that the actor exploited a chain of SimpleHelp vulnerabilities, and documented both data exfiltration and downstream ransomware impact. That case demonstrates supply-chain reach through legitimate remote-management infrastructure but does not establish SimpleHelp exploitation as DragonForce’s universal access method.

What type of group is it?

DragonForce is best characterized as a financially motivated ransomware group operating a flexible service and affiliate ecosystem. Core operators supply shared infrastructure and tooling; affiliates may conduct access, choose victims and present attacks under independent brands. The cartel label is the operation’s own marketing term, not evidence of centralized control over every affiliated actor. Public sources do not identify the core operators, establish their jurisdiction or support state sponsorship.

Incident claim

Impacted organizations

Impacted locations

Sources