DragonForce is a ransomware threat actor active in 2026 that publicly claims intrusions across a broad range of sectors and geographies, including manufacturing, financial services, telecommunications, technology, legal services, engineering, hospitality, and other business services. Reported victimology indicates opportunistic targeting rather than a narrowly focused vertical or regional specialization, with organizations observed in North America, Europe, Africa, the Middle East, Asia, and Latin America. DragonForce is associated with double-extortion style ransomware operations in which data theft and encryption are both used to pressure victims. Publicly claimed incidents indicate the group routinely presents compromises as both ransomware attacks and data breaches. In at least one documented intrusion culminating in DragonForce deployment, the ransomware stage followed an earlier access operation that began with exploitation of Citrix NetScaler infrastructure via CVE-2025-5777, consistent with a broader ecosystem in which initial access brokers obtain footholds and later hand them to ransomware operators or affiliates. Observed post-compromise tradecraft linked to an intrusion ending in DragonForce ransomware included credential access and lateral movement using Mimikatz, PsExec, and Impacket-based tooling, along with persistence through legitimate remote-management software. This suggests DragonForce operations can rely on common hands-on-keyboard enterprise intrusion methods rather than novel malware alone. Reporting also places DragonForce among active ransomware brands appearing in weekly leak-site claim tracking during mid-2026. Available information supports classifying DragonForce as an eCrime ransomware actor. No high-confidence public evidence in the provided material establishes it as a nation-state threat actor. Known alias usage in the available data is limited to the capitalization variant dragonforce/DragonForce.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 malware families attributed to this actor across reporting.
12 additional families tracked in Mallory.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
SimpleHelp RMM CVE-2024-57727 & CVE-2024-57728 DragonForce sophos.com
SimpleHelp RMM CVE-2024-57727 & CVE-2024-57728 DragonForce sophos.com
Researchers said the attackers used a new tool called Havoc Process Terminator to exploit a Huawei audio driver, tracked as HWAudioOs2Ec.sys. They also exploited three documented driver vulnerabilities CVE-2023-52271 in Topaz Antifraud, CVE-2025-61155 in Tower of Fantasy, and CVE-2025-1055 in K7 Security Anti-Malware.
The campaigns, uncovered in early 2025, leveraged a trio of flaws—CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728—to pivot from compromised RMM servers into victim networks with “minimal friction.”
Researchers said the attackers used a new tool called Havoc Process Terminator to exploit a Huawei audio driver, tracked as HWAudioOs2Ec.sys. They also exploited three documented driver vulnerabilities CVE-2023-52271 in Topaz Antifraud, CVE-2025-61155 in Tower of Fantasy, and CVE-2025-1055 in K7 Security Anti-Malware.
10 more CVEs tied to this actor tracked in Mallory.
90 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack resulting in a data breach against Petrini Valores in Argentina.
Conducting a ransomware attack against Sinai Grand Casino.
Conducting a ransomware attack against Southport Outdoor Living.
Conducting a ransomware attack against Metro Design Cente / Metro Design Center.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.