Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationransomware-tooling-evolutionendpoint-security-bypassunderground-data-leak

DragonForce Ransomware Operations and High-Profile Breaches

Updated 3mo agoFirst seen Dec 4, 20252 sources

DragonForce, a ransomware group that has evolved into a self-described "ransomware cartel," has intensified its global operations, targeting organizations with advanced tactics and forming alliances with other cybercriminal collectives. Security researchers have detailed how DragonForce leverages vulnerable drivers such as truesight.sys and rentdrv2.sys to disable security software and has improved its encryption methods to address previously exploited vulnerabilities. The group, which began by using the LockBit 3.0 builder and later adopted a modified Conti v3 source code, now operates a ransomware-as-a-service (RaaS) model, offering affiliates a significant share of profits and customizable tools to attract new participants. Notably, DragonForce has collaborated with groups like Scattered Spider and has been linked to the compromise of major organizations, including a high-profile breach of Marks & Spencer.

Recently, DragonForce claimed responsibility for a significant breach at Mobilelink USA, a major dealer for Cricket Wireless, exfiltrating 5.04 TB of data and threatening to leak sensitive information, including personally identifiable and financial data of millions of customers across 21 states. The group has also reportedly allied with other ransomware gangs such as Qilin and LockBit, and has taken over operations or leak sites from other ransomware groups like RansomHub, BlackLock, and Mamona. In 2025 alone, DragonForce has impacted at least 185 organizations, with most attacks occurring in the last six months, underscoring the growing threat posed by this increasingly organized and aggressive ransomware operation.

Share:
DragonForce Ransomware Operations and High-Profile Breaches
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Dec 3, 20257mo ago

DragonForce claims breach of Mobilelink USA

DragonForce claimed on its leak site that it breached Mobilelink USA, a major Cricket Wireless dealer, and exfiltrated 5.04 TB of data. The stolen information was said to potentially include PII and financial data affecting millions of Cricket Wireless customers across 21 states.

Marks & Spencer breach linked to DragonForce-Scattered Spider activity

The DragonForce and Scattered Spider partnership was tied to the high-profile breach of Marks & Spencer. Scattered Spider reportedly used tactics such as MFA fatigue, SIM swapping, and remote management tools before DragonForce ransomware was deployed.

DragonForce partners with Scattered Spider for intrusions

DragonForce partnered with the Scattered Spider threat group, combining Scattered Spider's social-engineering-led initial access methods with DragonForce's ransomware deployment. The collaboration enabled more coordinated and high-impact attacks.

DragonForce expands through alliances with other ransomware groups

DragonForce formed alliances with other ransomware actors, including Qilin and LockBit, and was reported to have taken over the RansomHub operation while compromising the leak sites of BlackLock and Mamona. This marked a significant expansion of its criminal ecosystem and operational reach.

DragonForce updates malware to improve evasion and encryption

By late 2025, DragonForce released newer variants that abused vulnerable drivers to disable security tools and improved encryption to fix flaws documented in earlier versions. These changes reflected a technical maturation of the ransomware.

Jan 1, 20233y ago

DragonForce ransomware emerges as a RaaS operation

DragonForce emerged in 2023 as a ransomware-as-a-service operation. It later evolved into a broader 'ransomware cartel' model designed to attract affiliates with high profit shares and customizable infrastructure.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

17 LINKEDOpen in app
Threat actors
2 linked
Malware
1 linked
Organizations
14 linked
DragonForceAmazonMegaAcronisLockBitQilinRansomHubBlackLockScattered SpiderCricket WirelessMamonaAcronis Threat Research Unit (TRU)Marks & SpencerMobilelink
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.