DragonForce is a ransomware family and associated ransomware-as-a-service operation active since late 2023. It has been described as operating both as a conventional affiliate-based RaaS program and, later, as a self-styled ransomware cartel. The malware lineage is strongly associated with leaked Conti source code, and some reporting also identifies overlap with LockBit 3.0-derived implementations, indicating code reuse and evolution across builds. DragonForce has been used in financially motivated intrusions involving data theft, encryption, and extortion, including campaigns linked to affiliates and collaborators such as Scattered Spider, as well as separate operators using modified DragonForce-derived code.
DragonForce targets Windows and Linux environments, with Linux variants supporting enterprise server use cases including VMware ESXi. Observed functionality includes file encryption, data exfiltration, shadow copy deletion, network-share encryption, optional filename encoding, and process termination for impact and defense suppression. Multiple analyses also report integrated bring-your-own-vulnerable-driver functionality used to disable or kill security tooling, showing a mature emphasis on defense evasion. In Windows intrusions, DragonForce activity has been accompanied by privilege escalation, remote administration tooling, credential access, reconnaissance, lateral movement, and persistence mechanisms established before ransomware deployment.
Delivery and initial access are affiliate-dependent rather than intrinsic to the encryptor itself. Reported intrusion paths associated with DragonForce deployments include exploitation of exposed edge infrastructure, hijacked authenticated sessions on Citrix NetScaler appliances, abuse of public-facing RDP, and access obtained through social engineering-heavy actors such as Scattered Spider. In one advanced intrusion against a U.S. services firm, operators paired DragonForce with a custom Go backdoor known as Backdoor.Turn that tunneled command-and-control traffic through Microsoft Teams TURN relay infrastructure, alongside DLL sideloading and BYOVD tradecraft, and maintained persistence for an extended period before encryption.
Victimology is broad and opportunistic, spanning business services, manufacturing, construction, technology, healthcare, retail, finance, logistics, and other sectors across multiple countries. DragonForce has been prominently associated with attacks on UK organizations and with extortion operations affecting enterprise environments. The malware is best understood as a capable modern ransomware family embedded in a broader criminal ecosystem of affiliates, access brokers, and cooperating extortion actors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The activity centers on CitrixBleed 2, tracked as CVE-2025-5777, which can expose memory from affected NetScaler ADC and Gateway appliances before a user signs in. That exposure lets attackers search for and reuse active session tokens. | In one incident, the operator progressed from initial access to ransomware deployment in under an hour. DragonForce was used in the most advanced case.
DragonForce ransomware is an advanced and competitive ransomware-as-a-service (RaaS) brand that first emerged in mid-2023.
DragonForce ransomware is an advanced and competitive ransomware-as-a-service (RaaS) brand that first emerged in mid-2023.
DragonForce ransomware is an advanced and competitive ransomware-as-a-service (RaaS) brand that first emerged in mid-2023.
“DragonForce ransomware was first identified in August 2023… DragonForce has two ransomware variants - one based on LockBit Ransomware and another based on the Conti Ransomware variant.”
“DragonForce ransomware was first identified in August 2023… DragonForce has two ransomware variants - one based on LockBit Ransomware and another based on the Conti Ransomware variant.”
“DragonForce ransomware was first identified in August 2023… DragonForce has two ransomware variants - one based on LockBit Ransomware and another based on the Conti Ransomware variant.”
“DragonForce ransomware was first identified in August 2023… DragonForce has two ransomware variants - one based on LockBit Ransomware and another based on the Conti Ransomware variant.”
“DragonForce ransomware was first identified in August 2023… DragonForce has two ransomware variants - one based on LockBit Ransomware and another based on the Conti Ransomware variant.”
Fortinet FortiOS CVE-2024-55591, a zero-day authentication bypass vulnerability disclosed in January 2025, had the highest count of ransomware groups attached to it as the year closed, with six named ransomware families (DragonForce, Hunters International, NightSpire, Qilin, RansomHub, and SuperBlack)...
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Criminal complaints against alleged Scattered Spider members and public reports reveal collaboration of the subclusters with ALPHV/Blackcat and Dragonforce.
Devman is a ransomware operator, believed to be located in Russia, who uses modified DragonForce code built on top of the leaked Conti source code.
The DragonForce Ransomware Group, first detected in December 2023, developed its own ransomware based on LockBit 3.0 (Black) and Conti Ransomware code.
The next step, as per the company’s blog post, the attackers stole confidential files and encrypted systems using DragonForce ransomware.
Since at least April 2025, the group has partnered with the DragonForce RaaS program, operated by the group we track as Slippery Scorpius, to extort victims. In one case, we observed attackers exfiltrating over 100 GB of data during a two-day period, with encryption via DragonForce ransomware deployment.
When DragonForce emerged in August 2023, it offered a traditional RaaS scheme. On March 19, 2025, the group announced a rebrand as a ‘cartel’ to expand its reach, hoping to emulate the success of LockBit and other mature ransomware-as-a-service (RaaS) groups.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The DragonForce ransomware group initially infiltrated the victim system network via a remote desktop server and attempted persistent logins using valid domain accounts (Domain Accounts, T1078.002).
When the “schedule_job” field in the Config information is enabled, the process of registering a job that runs with SYSTEM privileges to the scheduler is performed.
The DragonForce ransomware group initially infiltrated the victim system network via a remote desktop server and attempted persistent logins using valid domain accounts (Domain Accounts, T1078.002).
When the “schedule_job” field in the Config information is enabled, the process of registering a job that runs with SYSTEM privileges to the scheduler is performed.
DragonForce ransomware uses two methods to terminate predefined processes. The first method utilizes the BYOVD (Bring Your Own Vulnerable Driver) technique, exploiting vulnerable drivers...
All strings used by DragonForce ransomware are obfuscated and decrypted using a custom algorithm.
...some samples... were found to perform API resolving based on the MurMurHash2 algorithm to dynamically load the API.
Appendix C. MITRE ATT&CK ... (T1070.001) Clear Windows Event Logs
...collected Active Directory configuration (Domain Trust Discovery, T1482) and network information (System Network Configuration Discovery, T1016) via ADFind and netscanold.exe.
Appendix C. MITRE ATT&CK ... (T1082) System Information Discovery
Before performing encryption, a directory traversal is conducted to identify files to be encrypted.
In one incident, the operator progressed from initial access to ransomware deployment in under an hour. DragonForce was used in the most advanced case... executed a DragonForce ransomware file that encrypted the affected environment.
54 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
122 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware used in the final stage of the intrusion chain after exploitation of CitrixBleed 2, with the attackers executing a DragonForce ransomware file that encrypted the affected environment.
Ransomware deployed at the end of the intrusion chain after Citrix NetScaler access, privilege escalation, persistence, and lateral movement; in the most progressed case it encrypted the victim environment.
Ransomware family/group referenced as collaborating with Scattered Spider subclusters in ransomware deployment and monetization.
Ransomware used by Scattered Spider in attacks against British retailers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.