The four features of this adversary's intrusions under the Diamond Model — adversary, capability, infrastructure, victim — assembled from tracked data; pivot from any vertex to the others.
Adversary3
Who is behind the activity — operator vs. customer.
DragonForceDragonForceDragonForce Cartel
Capability22
Tradecraft, techniques, and tooling the adversary employs.
7 ATT&CK techniquesImpactCollectionCredential AccessDefense EvasionAdFindAdvanced IP ScannerPingCastleSoftPerfect NetScanADVobfuscator
Infrastructure
Physical/logical infrastructure used to deliver capability (C2, domains, relays).
No infrastructure indicators correlated in Radar yet.
Victim4
Targeting — sectors and geographies in scope.
Real estateconstructionchemical/logisticsSaudi Arabia
Operator ↔ CustomerOperator/affiliate model — the crew runs the intrusion; the RaaS brand and initial-access brokers are upstream parties.
Honesty note
Attribution ≠ confirmation. DragonForce is linked here via TTP overlap and shared infrastructure — not confirmed by original-source reporting. Treat this as a working hypothesis, not a settled fact.
The actor's techniques grouped into kill-chain phases — a partial order across phases; techniques within a phase are co-occurring, not sequenced. Export opens in CTID's Attack Flow Builder.
7 techniques across 4 of 7 stages · 3 of 6 pre-objective stages show known tradecraft — each a chance to break the chain before Actions on Objectives.
1Reconnaissance
2Weaponization1
T1588.001
3Delivery1
T1078
4Exploitation
5Installation1
T1656
6Command & Control
7Actions on Objectives4
T1005T1621T1490T1486
Honesty note
Phase groupings reflect ATT&CK tactic classification, not a confirmed operational timeline for DragonForce — see the competing-hypotheses breakdown for how confident this attribution really is.