DragonForce is a ransomware operation that re-emerged in 2025 as a 'cartel'-style affiliate model, gaining prominence through collaboration with the Scattered Spider intrusion set.
External aliases
via 1 crosswalk source
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
DragonForce appeared around 2023 and rebranded in 2025 into a 'ransomware cartel' model, recruiting affiliates with high revenue shares, custom encryptors, and shared leak infrastructure. Its encryptor lineage has been linked in reporting to leaked Conti/LockBit builder code, and its encryptors target Windows, Linux and ESXi environments.
The operation rose sharply in 2025, in part through tactical partnership with Scattered Spider (UNC3944 / Octo Tempest), including the widely reported intrusions against UK retailers such as Marks & Spencer. Reporting through 2025-2026 credits DragonForce with well over 200 published victims and a claimed alliance with LockBit and Qilin. Scattered Spider tradecraft feeding these intrusions emphasizes help-desk social engineering, MFA bypass, and cloud/identity abuse before ransomware deployment.
DragonForce's leak site has listed victims in Saudi Arabia among its international claims. Such listings are extortion allegations and should be treated as claims, not confirmed breaches, unless independently verified.
Notable campaigns
2025
UK retail intrusions with Scattered Spider
DragonForce ransomware was deployed in Scattered Spider-linked attacks on retailers including Marks & Spencer (partner attribution).
2025
Cartel rebrand
DragonForce restructured into a cartel-style affiliate model offering custom encryptors and shared infrastructure.