Skip to main content
Mallory
Back to threat actors
🇲🇾 MY2 malware families

DragonForce Malaysia

Also known asDragonForce Malaysia

DragonForce Malaysia is a pro-Palestinian hacktivist group that has conducted politically motivated operations targeting Israel and entities directly or indirectly supporting Israel. It returned for a third year with an anti-Israel campaign branded OpsPetir, which replaced its earlier OpsBedil branding and overlapped with the broader OpIsrael campaign. Reported early OpsPetir targets included Israeli universities and financial institutions, and expected target sectors also included religious organizations, healthcare, service providers, transportation entities, and government agencies. Reported DragonForce Malaysia activity focuses on threat messaging, mobilization, and disruptive operations rather than confirmed ransomware activity. Radware assessed that its likely attack methods include scanning, exploitation, data dumps, denial-of-service attacks, and website defacements. The group has used or promoted a DDoS tool called CyberTroopers, described as an obfuscated Python program with TCP, UDP, and HTTP flooding capabilities that can pull free proxy and SOCKS lists from free-proxy-list[.]net and proxyscrape[.]com to help randomize apparent attack origin and complicate Layer 7 mitigation. The group operates an active forum used for campaign announcements and discussion of tactics, techniques, and procedures, and also maintains a Telegram channel with content replicated to Discord and other social media platforms. It has been observed collaborating with T3 dimension Team, Reliks Crew, and AnonGhost. Known campaigns mentioned in the content include OpsBedil (launched in June 2021), OpsBedil Reloaded (April 2022), OpsPetir, and OpsPatuk targeting India. During the 28 February to 1 March 2026 Middle East escalation, DragonForce Malaysia was also named among hacktivist groups active or claiming activity. One report notes only an unconfirmed possibility of a relationship between DragonForce Malaysia and DragonForce ransomware; this linkage is not confirmed in the provided content.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Health Care Equipment & Services
  • Banks
  • Transportation
  • Government & Administration
  • Academia & Research

Where they target

Geographies tied to known operations.

  • 🇮🇱 Israel
  • 🇮🇳 India

Where they're from

Attributed origin per open-source reporting.

  • MY
MITRE ATT&CK

Tradecraft

8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

4 of 15 tactics9 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1190
Exploit Public-Facing Application
TA0007
Discovery
1 technique
T1046
Network Service Discovery
TA0011
Command and Control
1 technique
T1090
Proxy
T1090.003
Multi-hop Proxy
TA0040
Impact
4 techniques
T1491
Defacement
T1491.001
Internal Defacement
T1498×2
Network Denial of Service
T1499
Endpoint Denial of Service
T1565
Data Manipulation
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping8

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal2

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.