ZeroHour

dragonforce

ransomware group · aka DragonForce, DragonForce Ransomware, DragonForce Cartel · Malaysia (widely reported by vendors; leadership identity and exact origin not officially confirmed) · active since 2023-08

Victims · 7d
3▲1 vs prev. week
Victims · 30d
12active targets
Victims · 90d
71
All-time (tracked)
650since 2023-12-13
Last post
09-16 06:35UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

DragonForce is an active ransomware-as-a-service (RaaS) operation first observed in August 2023, widely reported to be Malaysia-linked, with some vendor research connecting its founders to the earlier 'Operation' (a.k.a. Operation Cronos) brand. It runs a 'cartel' model in which multiple affiliates share its encryptors and leak-site infrastructure, sometimes posting victims under their own branding, and it publicly recruited affiliates displaced by the 2024 LockBit and BlackCat/ALPHV law-enforcement takedowns. The group uses double extortion, publishing stolen victim data on its Tor leak blog, and provides encryptors for Windows, Linux, VMware ESXi, macOS, and NAS devices. It drew wide attention in 2025 when Scattered Spider-affiliated intrusions using its tooling hit major UK retailers, and it subsequently launched an updated RaaS panel and a speed-focused encryptor rework. Dashboard leak-site tracking shows sustained high-volume activity (76 victims in the past 90 days), confirming the group remains a major brand.

Tactics & tooling
  • RaaS 'cartel' model: shares encryptors and leak infrastructure with affiliates that may post victims under their own branding
  • Double extortion: exfiltrates data before encryption and publishes stolen files on its leak blog
  • Initial access via IT help-desk social engineering by affiliates (Scattered Spider in the 2025 UK retail incidents)
  • Exploitation of internet-facing edge devices and VPNs (e.g., SonicWall SSL VPN activity reported in 2024)
  • Multi-platform encryptors covering Windows, Linux, VMware ESXi, macOS, and NAS devices
  • 2025 encryptor rework adding distributed encryption across machines and partial-encryption options to accelerate attacks (vendor reporting)
  • Public recruiting and rebranding of affiliates from other ransomware ecosystems onto shared infrastructure
Targeted sectors
retailmanufacturingprofessional serviceslegal servicesfinancial servicestechnology and MSPsconstruction
Notable public victims

Marks & Spencer (2025), Co-op Group (2025), Harrods (2025)

CVEs linked to their intrusions
Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Accurate Lock and Hardware · May 14, 2024
Monocon International Refractory · May 14, 2024
Persyn · May 14, 2024
Watt Carmichael · May 14, 2024
Malone · May 14, 2024
Fullington Trailways · Apr 15, 2024
Deacon Jones · Apr 15, 2024
Kadushisoft · Apr 9, 2024
Saint Cecilia's Church of England School · Apr 9, 2024
Swansea & South Wales · Apr 9, 2024
MajuHome Concept · Apr 9, 2024
Team Locum · Apr 9, 2024
Rigcon · Apr 9, 2024
Vstblekinge Miljo · Apr 9, 2024
New Production Concept · Apr 9, 2024
PalauGov · Apr 7, 2024
Aussizz Group · Apr 5, 2024
Dunbier Boat Trailers · Mar 25, 2024
Greenline Service · Mar 25, 2024
Teton Orthopaedics · Mar 25, 2024
Jasper-Dubois County Public Library · Mar 19, 2024
Ward Transport & Logistics · Mar 3, 2024
Crystal Window & Door Systems · Mar 1, 2024
Faison · Feb 29, 2024
Erwat · Feb 29, 2024
Artissimo Designs · Feb 29, 2024
Compression Leasing Services · Feb 19, 2024
Westward 360 · Feb 19, 2024
Geologics · Jan 6, 2024
Ohio Lottery · Dec 27, 2023
ACE Air Cargo · Dec 21, 2023
Kinetic Leasing · Dec 21, 2023
Yakult Australia · Dec 20, 2023
Heart of Texas Region MHMR · Dec 13, 2023
PCTEL · Dec 13, 2023
Agl Welding Supply · Dec 13, 2023
Grayhill · Dec 13, 2023
Leedarson Lighting · Dec 13, 2023
Coca-Cola Singapore · Dec 13, 2023
Shorts · Dec 13, 2023
World Emblem International · Dec 13, 2023
The GBUAHN · Dec 13, 2023
Baden · Dec 13, 2023
Dafiti Argentina · Dec 13, 2023
Lunacon Construction Group · Dec 13, 2023
Tglt · Dec 13, 2023
Seven Seas · Dec 13, 2023
Decina · Dec 13, 2023
Cooper Research Technology · Dec 13, 2023
Greater Cincinnati Behavioral Health · Dec 13, 2023

In the newsAll →

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .