DragonForce is a financially motivated ransomware operation known for publishing victim claims and alleged stolen data through a leak-site model. It has been associated with ransomware incidents affecting organizations in financial services, construction, professional services, and manufacturing, including firms supporting aerospace and defense supply chains. Reported victim activity spans the United States, Brazil, Argentina, and the United Arab Emirates. DragonForce was reported as participating in a 2025 alliance with Qilin and LockBit. A separate actor using the Ransom Busters persona was assessed with moderate confidence to be a ransomware affiliate active across multiple ransomware-as-a-service ecosystems, including cases associated with DragonForce, Settra, and Anubis; this does not establish that all observed affiliate tradecraft is exclusive to DragonForce. DragonForce is also referred to as Dragon Force and Slippery Scorpius.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 malware families attributed to this actor across reporting.
12 additional families tracked in Mallory.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
SimpleHelp RMM CVE-2024-57727 & CVE-2024-57728 DragonForce sophos.com
SimpleHelp RMM CVE-2024-57727 & CVE-2024-57728 DragonForce sophos.com
Researchers said the attackers used a new tool called Havoc Process Terminator to exploit a Huawei audio driver, tracked as HWAudioOs2Ec.sys. They also exploited three documented driver vulnerabilities CVE-2023-52271 in Topaz Antifraud, CVE-2025-61155 in Tower of Fantasy, and CVE-2025-1055 in K7 Security Anti-Malware.
The campaigns, uncovered in early 2025, leveraged a trio of flaws—CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728—to pivot from compromised RMM servers into victim networks with “minimal friction.”
Researchers said the attackers used a new tool called Havoc Process Terminator to exploit a Huawei audio driver, tracked as HWAudioOs2Ec.sys. They also exploited three documented driver vulnerabilities CVE-2023-52271 in Topaz Antifraud, CVE-2025-61155 in Tower of Fantasy, and CVE-2025-1055 in K7 Security Anti-Malware.
10 more CVEs tied to this actor tracked in Mallory.
111 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Groupe de ransomware figurant parmi les acteurs les plus actifs recensés en juillet 2026.
Named as a member of a ransomware-operator alliance that included Qilin.
A ransomware group included among the principal groups attributed to July 2026 attacks.
Conducting a ransomware attack and associated data breach against Frato, with claims that the release includes company-wide data, financial documentation, shareholder information, and personal data of employees and clients.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.