◇ SIGN IN
← all actors
ransomware

DragonForce

activemedium confidence
Ransomware
DragonForceDragonForce Cartel
Attribution
RaaS / 'cartel' affiliate model (financially motivated, unattributed)
Origin
Unknown
First seen
2023
Last active
2026
Motivation
Financially motivated (ransomware)
Confidence
medium
MENA targeting
Saudi Arabia
Sectors
Real estate, construction, chemical/logistics

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting Saudi Arabia (Real estate, construction, chemical/logistics sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

DragonForce is a ransomware operation that re-emerged in 2025 as a 'cartel'-style affiliate model, gaining prominence through collaboration with the Scattered Spider intrusion set.

History

DragonForce appeared around 2023 and rebranded in 2025 into a 'ransomware cartel' model, recruiting affiliates with high revenue shares, custom encryptors, and shared leak infrastructure. Its encryptor lineage has been linked in reporting to leaked Conti/LockBit builder code, and its encryptors target Windows, Linux and ESXi environments.

The operation rose sharply in 2025, in part through tactical partnership with Scattered Spider (UNC3944 / Octo Tempest), including the widely reported intrusions against UK retailers such as Marks & Spencer. Reporting through 2025-2026 credits DragonForce with well over 200 published victims and a claimed alliance with LockBit and Qilin. Scattered Spider tradecraft feeding these intrusions emphasizes help-desk social engineering, MFA bypass, and cloud/identity abuse before ransomware deployment.

DragonForce's leak site has listed victims in Saudi Arabia among its international claims. Such listings are extortion allegations and should be treated as claims, not confirmed breaches, unless independently verified.

Notable campaigns

2025
UK retail intrusions with Scattered Spider
DragonForce ransomware was deployed in Scattered Spider-linked attacks on retailers including Marks & Spencer (partner attribution).
2025
Cartel rebrand
DragonForce restructured into a cartel-style affiliate model offering custom encryptors and shared infrastructure.
2025
Saudi leak-site listing
A Saudi organization appeared on DragonForce's leak site (claimed, not independently confirmed).

Known tooling · Ransomware Tool Matrix

Tools observed in intrusions leading to DragonForce's ransomware, per the community Ransomware Tool Matrix — observed use, not exhaustive. Snapshot 2026-08-07.

Discovery · 4
AdFindAdvanced IP ScannerPingCastleSoftPerfect NetScan
Defense Evasion · 5
ADVobfuscatorDarkside/TrueSight driver (BYOVD)Hangzhou Shunwang Technology driver (BYOVD)PCHunterProcessHacker
Credential Theft · 2
LaZagneMimikatz
OffSec · 1
Cobalt Strike
LOLBAS · 1
PsExec
Exfiltration · 2
MEGARClone

2 source reports · latest 29 October 2025

Claimed victims · 636 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

Claim volume · last 12 months
SONDJFMAMJJA
DateVictimCountrySector
Mike Graham Heating And Air ConditioningUSOther
P. A. Inc. (Performance Alloys)USManufacturing
EduSpaUSHospitality
Primary Eye CareUSHealthcare
TUI ChinaCNHospitality
Lamont PridmoreGB
www.mbmlawsc.comUSProfessional Services
RUS IndustrialUSManufacturing
Katathani Phuket Beach ResortTHHospitality
Deluxe Medical SupplyUSHealthcare
Syntron BioresearchUSHealthcare
ID engineeringIDManufacturing