DragonForce Ransomware Targets Critical Businesses to Exfiltrate Sensitive Data
DragonForce is a ransomware group that emerged in late 2023, posing a significant threat to businesses by combining data theft with file encryption.
DragonForce is a ransomware group that emerged in late 2023, posing a significant threat to businesses by combining data theft with file encryption.
The group employs a dual extortion strategy by stealing sensitive data, encrypting systems, and threatening to publish the information on dark web sites if victims do not comply with payment demands.
DragonForce has notably targeted the manufacturing and construction sectors, impacting several high-profile organizations. The group has demonstrated adaptability by refining its tools and transitioning from dedicated victim sites to a centralized domain for hosting leaked data.
Cybereason has highlighted this rapid evolution, indicating that it contributes to the persistent and growing risk DragonForce poses worldwide.
DragonForce operates as a ransomware-as-a-service (RaaS) platform, facilitating affiliate attacks across Windows, Linux, ESXi, BSD, and NAS systems.
The platform supports various encryption methods (full, header, and partial) and promotes automated processes for encryption, server management, and attack execution. Reported features include delayed-start options, multithreading for speed, detailed logging, and a “dry-run” mode to test attack flows without actual data encryption.
DragonForce is a ransomware group that emerged in late 2023, posing a significant threat to businesses by combining data theft with file encryption.
For ESXi environments, Cybereason notes command-line and configuration options that control targeting and behavior, including file-system search modes, delay timers, thread counts, and logging settings. These controls enable affiliates to tailor their impact (e.g., prioritizing VM infrastructure) while minimizing failures that could slow down ransomware deployment.
DragonForce has introduced a strategic shift, allowing affiliates to create their own brands under a “DragonForce ransomware cartel” umbrella while utilizing shared infrastructure and expertise. The group also introduced an automated registration service for new affiliates, eliminating previous approval steps, deposits, and vetting requirements.
DragonForce has announced a forthcoming product called “DragonForce – Atom” without providing technical details. A new service, “Company Data Audit,” aims to enhance extortion efforts by analyzing stolen data and creating negotiation materials, including risk reports and executive-facing letters.
DragonForce has engaged in public disputes with other ransomware operations, involving claims and counterclaims with RansomHub and the defacement of a competitor’s leak site. Cybereason notes that claims of an association between DragonForce and DragonForce Malaysia remain unsubstantiated, with DragonForce Malaysia publicly denying any affiliation in October 2025.
Cybereason observed behaviors consistent with real-world ransomware tactics, such as scanning SMB ports for reconnaissance and deleting Volume Shadow Copies using WMIC. The Cybereason platform detected the DragonForce payload, blocking shadow-copy deletion and file encryption activities.
Recommended steps include monitoring for DragonForce affiliate pre-ransomware behavior, enforcing multi-factor authentication, maintaining robust patch management, and ensuring reliable backups and tested restore processes. If suspicious activity is detected, it is advised to promptly involve Incident Response teams to investigate, contain, and remove the threat actor.
For users of the Cybereason Defense Platform, the report recommends enabling Anti-Malware, Anti-Ransomware with shadow copy protection, Application Control, and Variant Payload Prevention in prevent mode.
Based on reporting by GBHackers.
