DragonForce is a financially motivated ransomware and extortion operation active since late 2023 that has developed into one of the more prolific ransomware-as-a-service brands observed in 2026. It is commonly tracked as DragonForce, Dragon Force, and DragonForce Ransomware Cartel. Reporting has suggested possible ties to Malaysia, but this remains less certain than its established role as a criminal ransomware enterprise. DragonForce conducts double-extortion operations, combining data theft with encryption and threats to publish stolen information. Its victimology is broad and opportunistic, with observed targeting across healthcare, manufacturing, financial services, professional services, telecommunications, and other sectors. Public reporting in 2026 consistently places the group among the most active ransomware operations globally, with especially strong visibility in North America, Europe, and the UK and Ireland, while also appearing in EMEA healthcare targeting datasets. The operation appears to function through an affiliate model rather than as a single intrusion crew. Multiple analyses place DragonForce among the leading RaaS ecosystems by victim volume in 2026, and code-lineage reporting indicates that other actors and lockers have reused or inherited DragonForce ransomware components. DevMan, for example, was assessed to have malware lineage closely tied to DragonForce after earlier affiliate activity involving DragonForce and other major ransomware brands. DragonForce’s tradecraft is consistent with modern human-operated ransomware. It is associated with data exfiltration, enterprise-wide encryption, and coercive negotiation practices. Reporting also indicates use of large language models to improve extortion communications and negotiation messaging, suggesting operational adoption of AI as a force multiplier rather than a fundamentally new attack method. Separate reporting links DragonForce affiliates to use of externally sourced defense-evasion tooling, including EDR-killing utilities seen in broader ransomware ecosystems. Beyond conventional ransomware activity, DragonForce has also been linked to aggressive competition within the cybercriminal underground. It announced a project known as DragonBay and has been accused by rival actors of attacking competitor infrastructure. It has additionally been observed engaging in disruptive activity such as DDoS attacks and defacements against competing ransomware groups, indicating a willingness to use coercive tactics not only against victims but also against rival criminal operations. Overall, DragonForce is best characterized as a high-tempo, financially motivated ransomware cartel operating a mature extortion model with affiliates, broad sector targeting, double extortion, and occasional adversarial activity against competing groups. It remains a significant criminal threat in the global ransomware landscape.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 malware families attributed to this actor across reporting.
12 additional families tracked in Mallory.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
SimpleHelp RMM CVE-2024-57727 & CVE-2024-57728 DragonForce sophos.com
SimpleHelp RMM CVE-2024-57727 & CVE-2024-57728 DragonForce sophos.com
Researchers said the attackers used a new tool called Havoc Process Terminator to exploit a Huawei audio driver, tracked as HWAudioOs2Ec.sys. They also exploited three documented driver vulnerabilities CVE-2023-52271 in Topaz Antifraud, CVE-2025-61155 in Tower of Fantasy, and CVE-2025-1055 in K7 Security Anti-Malware.
The campaigns, uncovered in early 2025, leveraged a trio of flaws—CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728—to pivot from compromised RMM servers into victim networks with “minimal friction.”
Researchers said the attackers used a new tool called Havoc Process Terminator to exploit a Huawei audio driver, tracked as HWAudioOs2Ec.sys. They also exploited three documented driver vulnerabilities CVE-2023-52271 in Topaz Antifraud, CVE-2025-61155 in Tower of Fantasy, and CVE-2025-1055 in K7 Security Anti-Malware.
10 more CVEs tied to this actor tracked in Mallory.
92 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against Syntron Bioresearch.
Conducting a ransomware attack resulting in a data breach against Deluxe Medical Supply, a US healthcare supply distributor.
Referenced as a prior affiliate relationship of DevMan and as the ransomware lineage most closely resembling DevMan's locker.
Conducting a ransomware attack against ID Engineering & Automated Systems, a manufacturing-sector organization.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.