DragonForce is a ransomware and extortion group active in 2026 and commonly referred to as DragonForce or DragonForce ransomware cartel. It operates as a criminal enterprise that publicly claims victims across multiple regions and sectors, including manufacturing, telecommunications, financial services, hospitality, legal services, engineering, consumer services, and technology-related organizations. DragonForce has been observed using double-extortion style tactics centered on data theft and public leak-site pressure, and it has also been associated with broader extortion activity that includes psychological coercion during negotiations. Reporting indicates the group has used large language models to generate more plausible and persuasive extortion messaging, including pressure tactics framed to increase victim anxiety and urgency. Operationally, DragonForce has been linked to post-compromise ransomware deployment following upstream access operations. In one documented intrusion chain, access originated through exploitation of Citrix NetScaler systems vulnerable to CVE-2025-5777, after which the operator obtained SYSTEM privileges, established persistence through legitimate remote-management software, and later used PsExec, Impacket-based tooling, and Mimikatz for lateral movement and credential access before deploying DragonForce ransomware. This suggests DragonForce can appear either as the final-stage ransomware payload used by an affiliate or partner, or as part of a broader access-and-extortion ecosystem involving initial access brokers. The group has also been associated with aggressive competition inside the ransomware ecosystem. DragonForce announced a project called DragonBay and was accused by RansomHub of attacking rival infrastructure. It has additionally been observed conducting disruptive activity against competing ransomware actors, including distributed denial-of-service attacks and website defacements targeting groups such as BlackLock and Mamona, with possible related activity affecting Everest and LockBit. These behaviors indicate that DragonForce is not limited to victim extortion and may also engage in coercive or retaliatory operations against other criminal groups. By mid-2026, DragonForce ranked among the more active ransomware actors in public victim reporting, showing steady growth and placing near the top tier of groups by claimed volume in some industry tracking. Known aliases include dragon_force, DragonForce ransomware cartel, and Dragon Force ransomware group. Available information supports classification of DragonForce as a financially motivated cybercriminal ransomware operation rather than a confirmed nation-state actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 malware families attributed to this actor across reporting.
12 additional families tracked in Mallory.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
SimpleHelp RMM CVE-2024-57727 & CVE-2024-57728 DragonForce sophos.com
SimpleHelp RMM CVE-2024-57727 & CVE-2024-57728 DragonForce sophos.com
Researchers said the attackers used a new tool called Havoc Process Terminator to exploit a Huawei audio driver, tracked as HWAudioOs2Ec.sys. They also exploited three documented driver vulnerabilities CVE-2023-52271 in Topaz Antifraud, CVE-2025-61155 in Tower of Fantasy, and CVE-2025-1055 in K7 Security Anti-Malware.
The campaigns, uncovered in early 2025, leveraged a trio of flaws—CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728—to pivot from compromised RMM servers into victim networks with “minimal friction.”
Researchers said the attackers used a new tool called Havoc Process Terminator to exploit a Huawei audio driver, tracked as HWAudioOs2Ec.sys. They also exploited three documented driver vulnerabilities CVE-2023-52271 in Topaz Antifraud, CVE-2025-61155 in Tower of Fantasy, and CVE-2025-1055 in K7 Security Anti-Malware.
10 more CVEs tied to this actor tracked in Mallory.
91 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against NewNet.
Ransomware/extortion group showing steady growth and using LLMs to improve social engineering and ransom negotiation pressure.
Conducting a ransomware attack resulting in a data breach against Petrini Valores in Argentina.
Conducting a ransomware attack against Sinai Grand Casino.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.