Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationperimeter-device-exposureendpoint-security-bypassthird-party-vendor-breach

DragonForce affiliates intensify UK ransomware campaign using edge-device exploits

Updated 3d agoFirst seen Jun 17, 20266 sources

DragonForce affiliates sustained a broad ransomware and extortion campaign against UK organizations in May 2026, publicly naming seven UK victims on the group’s Tor leak site and posting 22 victims globally in a single day, including four UK firms. Reported victims spanned professional services, finance, logistics, construction, technology, and luxury retail, underscoring the group’s opportunistic targeting rather than a focus on one vertical. Helix International drew particular concern because of its role as a managed service provider with medium, large, and Fortune 500 clients, raising the risk of downstream compromise across customer environments.

Public reporting and curated intrusion data tie DragonForce activity to exploitation of exposed remote access and internet-facing systems, including Ivanti Connect Secure, FortiOS, FortiProxy, SonicOS SSL-VPN, Apache Log4j, Microsoft SmartScreen, and SimpleHelp RMM vulnerabilities. Tooling observed in DragonForce-linked intrusions includes utilities for discovery, remote management, credential theft, defense evasion, LOLBAS abuse, and exfiltration, while affiliates have also been linked to BYOVD techniques to disable or bypass EDR and antivirus protections. Prior reporting further connected DragonForce affiliates attributed to Scattered Spider to attacks on major UK retailers including M&S, Co-op, and Harrods.

Share:
DragonForce affiliates intensify UK ransomware campaign using edge-device exploits
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
May 27, 202626d ago

DragonForce posts 22 victims globally in one day

On 2026-05-27, DragonForce posted 22 victims globally on its leak site, including four UK firms. The reporting highlighted this as evidence of accelerating campaign activity.

UK Cybercrime Journal: Sustained DragonForce Campaign
May 26, 202627d ago

Community report documents DragonForce intrusion at small UK victim

A community incident report describes a DragonForce ransomware intrusion against a small UK organization in April 2025. The attackers reportedly used SimpleHelp and AnyDesk, deployed Cobalt Strike, abused PowerShell, stole Veeam credentials, used the KslD.sys BYOVD driver to disable Microsoft Defender protections, and exfiltrated data with Restic before ransomware execution.

Ransomware-Tool-Matrix/CommunityReports/CR-021-DRAGONFORCE-APR-2025.md at main · BushidoUK/Ransomware-Tool-Matrix · GitHub
Jun 1, 20251y ago

Scattered Spider-linked affiliates use DragonForce in UK retail attacks

Prior reporting cited in the references says affiliates attributed to Scattered Spider used DragonForce in attacks on major UK retailers including M&S, Co-op, and Harrods. The activity is anchored to June 2025 in the source content.

UK Cybercrime Journal: Sustained DragonForce Campaign
Oct 27, 20224y ago

DragonForce claims seven UK victims during May 2026

Throughout May 2026, DragonForce affiliates publicly claimed seven UK-based victims on their Tor leak site. The affected UK organizations spanned sectors including professional services, finance, logistics, construction, technology, and luxury retail.

UK Cybercrime Journal: Sustained DragonForce Campaign

DragonForce becomes active as a ransomware-as-a-service operation

Reporting describes DragonForce as an opportunistic ransomware-as-a-service threat actor that has been active since late 2023. Affiliates commonly exploit exposed remote access infrastructure and compromised credentials.

UK Cybercrime Journal: Sustained DragonForce Campaign
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

63 LINKEDOpen in app
Threat actors
2 linked
Affected products
8 linked
Veeam Backup & ReplicationFortiosSsl VpnFortiproxyPsexecAnydeskAmazon Simple Storage ServiceAdvanced Ip Scanner
Organizations
30 linked
FortinetIvantiHarrodsVeeam SoftwareSonicwallMarks & SpencerCo-opCult WinesRefreshment SystemsPracticusERHWSMHELIX INTERNATIONALArsenal ScaffoldTrend MicroSimpleHelpSoftperfectMegaBleepingComputerAmazon Web ServicesApache Software FoundationMicrosoft CorporationAnyDesk Software GmbHHuntressGroup-IBWasabi TechnologiesSophosCurated IntelligenceZensecHangzhou Shunwang Technology
Breaches
10 linked
PRACTICUS-2026-06HARRODS-2026-05MARKSSPENCER-2026-06PRACTICUS-2022-10OHIOLOTTERY-2026-06CO-OP-2026-06ADVANCEDMEDICALCONSULTANTS-2026-05ADVANCEDHEALTH-2026-05HARRODS-2026-06HEALTHCARERETROACTIVEAUDITS-2026-06
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.