DragonForce affiliates intensify UK ransomware campaign using edge-device exploits
DragonForce affiliates sustained a broad ransomware and extortion campaign against UK organizations in May 2026, publicly naming seven UK victims on the group’s Tor leak site and posting 22 victims globally in a single day, including four UK firms. Reported victims spanned professional services, finance, logistics, construction, technology, and luxury retail, underscoring the group’s opportunistic targeting rather than a focus on one vertical. Helix International drew particular concern because of its role as a managed service provider with medium, large, and Fortune 500 clients, raising the risk of downstream compromise across customer environments.
Public reporting and curated intrusion data tie DragonForce activity to exploitation of exposed remote access and internet-facing systems, including Ivanti Connect Secure, FortiOS, FortiProxy, SonicOS SSL-VPN, Apache Log4j, Microsoft SmartScreen, and SimpleHelp RMM vulnerabilities. Tooling observed in DragonForce-linked intrusions includes utilities for discovery, remote management, credential theft, defense evasion, LOLBAS abuse, and exfiltration, while affiliates have also been linked to BYOVD techniques to disable or bypass EDR and antivirus protections. Prior reporting further connected DragonForce affiliates attributed to Scattered Spider to attacks on major UK retailers including M&S, Co-op, and Harrods.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
5 events from the most recent confirmed update back to the earliest known activity.
DragonForce posts 22 victims globally in one day
On 2026-05-27, DragonForce posted 22 victims globally on its leak site, including four UK firms. The reporting highlighted this as evidence of accelerating campaign activity.
Community report documents DragonForce intrusion at small UK victim
A community incident report describes a DragonForce ransomware intrusion against a small UK organization in April 2025. The attackers reportedly used SimpleHelp and AnyDesk, deployed Cobalt Strike, abused PowerShell, stole Veeam credentials, used the KslD.sys BYOVD driver to disable Microsoft Defender protections, and exfiltrated data with Restic before ransomware execution.
Scattered Spider-linked affiliates use DragonForce in UK retail attacks
Prior reporting cited in the references says affiliates attributed to Scattered Spider used DragonForce in attacks on major UK retailers including M&S, Co-op, and Harrods. The activity is anchored to June 2025 in the source content.
DragonForce claims seven UK victims during May 2026
Throughout May 2026, DragonForce affiliates publicly claimed seven UK-based victims on their Tor leak site. The affected UK organizations spanned sectors including professional services, finance, logistics, construction, technology, and luxury retail.
DragonForce becomes active as a ransomware-as-a-service operation
Reporting describes DragonForce as an opportunistic ransomware-as-a-service threat actor that has been active since late 2023. Affiliates commonly exploit exposed remote access infrastructure and compromised credentials.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
6 references tracked. Mallory keeps watching after this page renders.
UK Cybercrime Journal: Sustained DragonForce Campaign - Malware News - Malware Analysis, News and Indicators
malware.news
Open sourceRansomware.live: dragonforce
ransomware.live
Open sourceRansomware-Tool-Matrix/CommunityReports/CR-021-DRAGONFORCE-APR-2025.md at main · BushidoUK/Ransomware-Tool-Matrix · GitHub
github.com
Open sourceRansomware-Tool-Matrix/GroupProfiles/DragonForce.md at main · BushidoUK/Ransomware-Tool-Matrix · GitHub
github.com
Open sourceRansomware-Vulnerability-Matrix/GroupProfiles/DragonForce.md at main · BushidoUK/Ransomware-Vulnerability-Matrix · GitHub
github.com
Open sourceUK Cybercrime Journal: Sustained DragonForce Campaign
blog.bushidotoken.net
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


