Water Tambanakua is the threat group tracked as operating the DragonForce ransomware enterprise. DragonForce was identified in 2023 and later expanded into a ransomware-as-a-service operation, advertising an affiliate program on the Russian-language RAMP cybercrime forum. The operation is associated with a double-extortion model that combines file encryption with data theft and threats to publish stolen information on leak infrastructure. In 2025, the group publicly promoted a broader white-label or “ransomware cartel” model that allowed affiliates to operate under their own brands while using DragonForce tooling and services. The group has primarily targeted industrial and manufacturing organizations, with victim concentration reported most heavily in North America and secondarily in Europe. Its tradecraft includes initial access through exposed remote access services, especially RDP, as well as social engineering. Persistence has been achieved through valid accounts, scheduled tasks, services, and registry-based autoruns. Lateral movement and post-compromise activity have involved RDP and common post-exploitation tooling such as Cobalt Strike. Reported defense-evasion behavior includes deletion of shadow copies, termination of running processes, and use of bring-your-own-vulnerable-driver techniques. DragonForce has operated multiple ransomware variants, including one derived from the leaked LockBit 3.0 builder and another based on a Conti-derived codebase. Reporting has linked the ecosystem to other ransomware brands and criminal networks including LockBit, Conti, BlackLock or Mamona, Qilin, Ransombay, Ransomhub, Devman, DragonForce Malaysia, and deployments associated with Scattered Spider. The operation has also used coercive pressure tactics beyond encryption, including victim intimidation calls and affiliate-facing services designed to generate tailored extortion materials. The actor’s dominant motivation is financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.