DragonForce Ransomware Group Expands Its Influence with Cartel-like Operations and Targeting 363 Companies Since 2023
DragonForce has emerged as a significant entity in the cybercrime sector since December 2023. Operating under a Ransomware-as-a-Service (RaaS) model, the group positions itself as a "cartel" to enhance power and influence. This strategy attracts numerous…
DragonForce has emerged as a significant entity in the cybercrime sector since December 2023. Operating under a Ransomware-as-a-Service (RaaS) model, the group positions itself as a "cartel" to enhance power and influence. This strategy attracts numerous affiliates and sets them apart from conventional criminal organizations. Their tactics have evolved, presenting a persistent threat to global enterprises.
The group utilizes dark web forums such as BreachForums, RAMP, and Exploit for recruitment and promotion. They offer unique tools, including "RansomBay" for customized payload generation and harassment calling services to apply pressure on victims. These methods are designed to increase the psychological and financial impact on targeted entities, resulting in higher payment success rates. DragonForce provides data analysis support and team coordination tools, offering a comprehensive suite comparable to established software enterprises.
According to S2W analysts, DragonForce targeted 363 companies between December 2023 and January 2026. The frequency of attacks has increased, peaking in December 2025 with 35 victims in a single month, indicating their expanding operational capacity and intent to scale attacks across various industries.
DragonForce has emerged as a significant entity in the cybercrime sector since December 2023.
DragonForce engages in adversarial relationships with rival ransomware groups and occasionally launches infrastructure-level attacks against competitors. They also form alliances to strengthen their ecosystem position, demonstrating their ambition to dominate the RaaS economy through both cooperation and conflict.
Technical Analysis of Windows Binaries
Recent assessments of DragonForce Windows binaries indicate that while encryption routines and process termination methods remain consistent, significant structural updates have been made. The ransomware employs the Bring Your Own Vulnerable Driver (BYOVD) technique to neutralize security processes, ensuring successful encryption. The metadata structure appended to encrypted files has been modified, with the "Encryption Ratio" field expanded from one byte to four bytes, increasing the total metadata size to 537 bytes.
The latest builder version includes a beta feature called "encryption_rules," enabling operators to override encryption modes for specific file extensions. If no specific rule is defined, the malware applies full, partial, or header-based encryption based on file size. Upon execution, the ransomware decrypts its embedded configuration using the ChaCha8 algorithm before initiating routines. This new configuration option allows attackers to optimize the speed and severity of the encryption process based on the victim's environment.
Based on reporting by Cyber Security News.
