DragonForce Ransomware Group Targets 363 Companies, Expands Cartel-Like Operations Since 2023
DragonForce is a ransomware operation that has transitioned into a cartel-style structure, expanding its influence within the cybercrime ecosystem since late 2023. Operating under a Ransomware-as-a-Service (RaaS) model, it serves as a platform for other…
DragonForce is a ransomware operation that has transitioned into a cartel-style structure, expanding its influence within the cybercrime ecosystem since late 2023. Operating under a Ransomware-as-a-Service (RaaS) model, it serves as a platform for other threat actors and affiliates. The group's infrastructure includes the “RansomBay” service, allowing partners to generate customized payloads and configure attacks.
The group initiated its activities with its first victim appearing on its public Data Leak Site (DLS) on December 6, 2023. Between December 2023 and January 2026, DragonForce disclosed 363 victim organizations on its DLS, with a notable increase in activity starting in 2025. In December 2025, the group reached its peak with 35 victims disclosed in a single month. High-profile attacks have been recorded in sectors such as retail, manufacturing, and services.
DragonForce continues to refine its malware and affiliate tools. Recent updates have introduced features such as an extension-based encryption mode, allowing operators to choose full, partial, or header-only encryption per file type. The ransomware is cross-platform, with Windows and Linux versions sharing core encryption and configuration logic. The ESXi variant includes capabilities for virtual machine shutdown and environment collection, enhancing disruption in virtualized environments.
Operating under a Ransomware-as-a-Service (RaaS) model, it serves as a platform for other threat actors and affiliates.
The affiliate panel provides extensive capabilities, including victim management, payload generation, team coordination, content and leak publishing, and integrated support ticket handling for affiliates. Recent modifications have removed certain features from the interface, although some processes remain embedded in newly generated binaries.
DragonForce maintains an active presence on major dark web forums, including BreachForums, RAMP, and Exploit, where it leaks data, recruits affiliates, and markets its services. The group has engaged in both cooperative and adversarial interactions with other cybercrime entities, underscoring its embedded role in the ransomware ecosystem.
Ongoing updates to DragonForce’s tools and strategies, combined with its cartel branding and aggressive targeting of rivals, indicate that it remains a significant threat in the ransomware landscape through 2026.
Based on reporting by GBHackers.
