dragonforce

First seen
2023-11-15 00:00:00
Malware type
ransomware
Family
Malware family
Last IoC activity
2026-07-20 15:59:15
Profile updated
2026-07-07 13:19:06

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:my country_code:sa

Context

Research on the operators of the DragonForce ransomware was conducted, and it was identified that the group emerged around mid-November 2023. They employ the same method as many other ransomware groups, using double extortion in their attacks, i.e., data encryption and extortion for the publication of the attacks. Initially, according to research, it was identified that another hacktivist group, also named DragonForce and based in Malaysia, conducted several campaigns in 2021 and 2022 against various government organizations and agencies across the Middle East and Asia. Additionally, the hacktivist group announced in 2022 its intention to initiate ransomware attacks. However, due to the limitation and difficulty in obtaining substantial information, no direct link could be established. The activities of the DragonForce ransomware group were identified in November 2023 through a clandestine forum, where they announced their victims via data leaks. Some samples related to the DragonForce ransomware group were obtained, and it was concluded that the group uses a binary (ransomware) based on LockBit Black. In other words, this threat group took advantage of the previously leaked builder from another ransomware group, LockBit, and incorporated these samples into their attacks to encrypt data. The company Cyble published an analysis indicating that the ransomware used by DragonForce has a 99% similarity to the LockBit Black ransomware, suggesting the use of the leaked builder. It is worth noting that the ransomware performs the entire operational routine, terminating processes, encrypting specific files, and subsequently creating a ransom note for the victim.

Detection coverage

  • 1 YARA rules

Used by threat actors

  • DragonForce SimpleHelp Vulnerabilities MSP Attack (campaign)

Detection rules

  • MALPEDIA_Win_Dragonforce_Auto (yara-rule)

Reports & references

  • cloud.google.com — Unc3944 Proactive Hardening Recommendations (report)
  • ransomlook.io — Dragonforce (report)
  • ransomware.live — Dragonforce (report)
  • sentinelone.com — Dragonforce Ransomware Gang From Hacktivists To High Street Extortionists (report)
  • barracuda.com — Dragonforce Ransomware Cartel Vs Everybody (report)
  • secureworks.com — Ransomware Groups Evolve Affiliate Models (report)
  • reuters.com — Ms Cyberattack Was Carried Out By Dragonforce Chairman Says 2025 07 08 (report)
  • ft.com — 22Cb54Ef 1611 4Aef B671 16316280E3Fb (report)
  • scworld.com — Dragonforce Victimization On The Rise Report Finds (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Dragonforce (report)
  • medium.com — Detailed Analysis Of Dragonforce Ransomware 25D1A91A4509 (report)
  • idanmalihi.com — Dragonforce Ransomware Unveiling Its Tactics And Impact (report)
  • levelblue.com — The Godfather Of Ransomware Inside Dragonforces Cartel Ambitions (report)

External references