Sunday, September 13, 2026

DragonForce Ransomware Targets Critical Businesses to Exfiltrate Sensitive Data

DragonForce is a ransomware group that emerged in late 2023 and has grown into a serious threat to businesses by combining data theft with file encryption.

The group uses dual extortion: it steals sensitive data, encrypts systems, and then threatens to publish the stolen information on dark web leak sites if victims do not pay.​

DragonForce has targeted multiple sectors, with a notable focus on manufacturing and construction, and it has impacted high-profile organizations.

The group has also shown it can adapt quickly by refining its tooling and shifting from dedicated victim sites to a centralized domain for hosting leaked data.

Cybereason notes this rapid evolution helps keep DragonForce a persistent, growing risk worldwide.​

RaaS platform and features

DragonForce operates as a ransomware-as-a-service (RaaS) platform that helps affiliates run attacks across Windows, Linux, ESXi, BSD, and NAS systems.

DragonForce’s list of key features posted on a dark web forum (Source : LevelBlue).
 DragonForce’s list of key features posted on a dark web forum (Source : LevelBlue).

The platform supports multiple encryption approaches (full, header, and partial encryption) and promotes automation for encryption, server management, and attack execution.

Reported features include delayed-start options, multithreading for speed, detailed logging, and a “dry-run” mode that tests an attack flow without actually encrypting data.​

For ESXi environments, Cybereason highlights command-line and configuration options that control targeting and behavior, including file-system search modes, delay timers, thread counts, logging settings, and allows for paths, extensions, filenames, and virtual machines.

These controls can help affiliates tailor impact (for example, prioritizing VM infrastructure) while reducing noisy failures that slow down ransomware deployment.​

Ransomware client builder  (Source : LevelBlue).
Ransomware client builder (Source : LevelBlue).

DragonForce has announced a strategic shift: affiliates can create their own brands under a “DragonForce ransomware cartel” umbrella and run their own projects while still using shared infrastructure and experience.

The group also introduced an automated registration service for new affiliates, reducing prior friction like approval steps, deposits, and vetting.

DragonForce has teased an upcoming product called “DragonForce – Atom,” but did not publish technical details in the cited analysis.​

The same reporting describes ecosystem “professionalization,” including a “Company Data Audit” service intended to strengthen extortion by analyzing stolen data and producing negotiation materials like risk reports, call scripts, and executive-facing letters.

DragonForce has also engaged in public disputes with other ransomware operations, including claims and counterclaims involving RansomHub and the defacement of a competitor’s leak site.

RansomHub publicly denied that it joined DragonForce (Source : LevelBlue).
 RansomHub publicly denied that it joined DragonForce (Source : LevelBlue).

Cybereason further notes claims of a relationship between DragonForce Malaysia and the ransomware group remain unsubstantiated, and DragonForce Malaysia publicly denied affiliation in October 2025.​

What defenders should do

Cybereason observed behaviors aligned with real-world ransomware playbooks, including scanning SMB ports for reconnaissance and deleting Volume Shadow Copies using WMIC (for example, wmic.exe shadowcopy where “ID='{id}'” delete).

Encrypted files (Source : LevelBlue).
Encrypted files (Source : LevelBlue).

The analysis states the Cybereason platform detected the DragonForce payload and blocked shadow-copy deletion and file encryption activity.​

Practical steps recommended include hunting for DragonForce affiliate pre-ransomware behavior, enforcing MFA, maintaining strong patch management, and ensuring reliable backups and tested restore processes.

If suspicious activity is found, the guidance advises quickly involving Incident Response to investigate, contain, and remove the threat actor.

For Cybereason Defense Platform users, the report recommends enabling Anti-Malware, Anti-Ransomware (PRP) with shadow copy protection, Application Control, and Variant Payload Prevention in prevent mode.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Related Articles

Recent News