DragonForce is a ransomware family and ransomware-as-a-service operation active since late 2023 that presents itself as a cartel-style ecosystem for affiliates. The malware and its surrounding service infrastructure have been linked to code overlap with leaked Conti source code and, in some reporting, LockBit 3.0 Black-derived components. DragonForce supports both Windows and Linux builds, including variants used against VMware ESXi environments, and has been used in enterprise intrusions across multiple sectors and countries.
DragonForce is designed to encrypt data and support double-extortion operations involving theft of confidential information prior to encryption. Reported capabilities include network-share encryption, deletion of shadow copies, process termination for security-tool disruption, and configurable encryption behavior. Analysis of generated samples indicates continued integration of bring-your-own-vulnerable-driver techniques for defense evasion and security-process termination. Linux variants have been observed supporting ESXi-focused functionality such as virtual machine shutdown prior to encryption.
Operational reporting ties DragonForce to hands-on intrusions involving credential access, lateral movement, and post-compromise tooling before ransomware deployment. In observed cases, operators or affiliates used utilities such as PsExec, Impacket tooling, Mimikatz, PowerShell, and remote desktop access to expand control in victim environments. DragonForce has also been associated with custom malware used for persistence and covert command-and-control, including a Go-based backdoor that tunneled traffic through Microsoft Teams TURN relay infrastructure, as well as DLL sideloading and BYOVD-based defense evasion during a prolonged intrusion at a U.S. services firm.
Initial access associated with DragonForce deployments has included exploitation of exposed enterprise services and brokered access. One recurring 2026 intrusion pattern involved exploitation of Citrix NetScaler session-leakage vulnerabilities to hijack already authenticated sessions, followed by local privilege escalation, creation of rogue administrator accounts, installation of legitimate remote-management tools, and eventual DragonForce deployment in the most advanced case. Separate reporting and law-enforcement guidance also link DragonForce use to Scattered Spider-associated operations, including attacks on UK retailers and encryption of VMware ESXi servers.
DragonForce occupies a notable place in the contemporary ransomware ecosystem because it combines commodity affiliate-driven extortion with increasingly sophisticated tradecraft, including custom tooling, persistence mechanisms, and advanced defense evasion. It has maintained relationships, rivalries, or overlap with other ransomware and cybercrime actors, and has been used both directly by its operators and in modified form by related ransomware actors such as DevMan.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attack chain begins with exploitation of the “CitrixBleed 2” vulnerability in Citrix NetScaler appliances... Huntress assesses with high confidence that the activity is the work of an initial access broker (IAB) weaponising CVE-2025-5777... A pre-auth memory leak that defeats MFA CVE-2025-5777, dubbed CitrixBleed 2... is a pre-authentication memory-overread affecting NetScaler ADC and Gateway when configured as a Gateway or AAA virtual server. | ...in its most advanced form, ends in DragonForce ransomware... In the most progressed case, the operator used PsExec, Impacket-based tooling and Mimikatz for lateral movement and credential access before deploying a DragonForce ransomware binary...
DragonForce ransomware is an advanced and competitive ransomware-as-a-service (RaaS) brand that first emerged in mid-2023.
DragonForce ransomware is an advanced and competitive ransomware-as-a-service (RaaS) brand that first emerged in mid-2023.
DragonForce ransomware is an advanced and competitive ransomware-as-a-service (RaaS) brand that first emerged in mid-2023.
“DragonForce ransomware was first identified in August 2023… DragonForce has two ransomware variants - one based on LockBit Ransomware and another based on the Conti Ransomware variant.”
“DragonForce ransomware was first identified in August 2023… DragonForce has two ransomware variants - one based on LockBit Ransomware and another based on the Conti Ransomware variant.”
“DragonForce ransomware was first identified in August 2023… DragonForce has two ransomware variants - one based on LockBit Ransomware and another based on the Conti Ransomware variant.”
“DragonForce ransomware was first identified in August 2023… DragonForce has two ransomware variants - one based on LockBit Ransomware and another based on the Conti Ransomware variant.”
“DragonForce ransomware was first identified in August 2023… DragonForce has two ransomware variants - one based on LockBit Ransomware and another based on the Conti Ransomware variant.”
Fortinet FortiOS CVE-2024-55591, a zero-day authentication bypass vulnerability disclosed in January 2025, had the highest count of ransomware groups attached to it as the year closed, with six named ransomware families (DragonForce, Hunters International, NightSpire, Qilin, RansomHub, and SuperBlack)...
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Criminal complaints against alleged Scattered Spider members and public reports reveal collaboration of the subclusters with ALPHV/Blackcat and Dragonforce.
Devman is a ransomware operator, believed to be located in Russia, who uses modified DragonForce code built on top of the leaked Conti source code.
The DragonForce Ransomware Group, first detected in December 2023, developed its own ransomware based on LockBit 3.0 (Black) and Conti Ransomware code.
Since at least April 2025, the group has partnered with the DragonForce RaaS program, operated by the group we track as Slippery Scorpius, to extort victims. In one case, we observed attackers exfiltrating over 100 GB of data during a two-day period, with encryption via DragonForce ransomware deployment.
When DragonForce emerged in August 2023, it offered a traditional RaaS scheme. On March 19, 2025, the group announced a rebrand as a ‘cartel’ to expand its reach, hoping to emulate the success of LockBit and other mature ransomware-as-a-service (RaaS) groups.
DragonForce posted 101 victims in Q1 2026 (an increase of 29% compared to Q4 2025), with a steep climb from 10 victims in January to 35 in February and 56 in March.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
The DragonForce ransomware group initially infiltrated the victim system network via a remote desktop server and attempted persistent logins using valid domain accounts (Domain Accounts, T1078.002).
When the “schedule_job” field in the Config information is enabled, the process of registering a job that runs with SYSTEM privileges to the scheduler is performed.
The DragonForce ransomware group initially infiltrated the victim system network via a remote desktop server and attempted persistent logins using valid domain accounts (Domain Accounts, T1078.002).
When the “schedule_job” field in the Config information is enabled, the process of registering a job that runs with SYSTEM privileges to the scheduler is performed.
DragonForce ransomware uses two methods to terminate predefined processes. The first method utilizes the BYOVD (Bring Your Own Vulnerable Driver) technique, exploiting vulnerable drivers...
All strings used by DragonForce ransomware are obfuscated and decrypted using a custom algorithm.
...some samples... were found to perform API resolving based on the MurMurHash2 algorithm to dynamically load the API.
Appendix C. MITRE ATT&CK ... (T1070.001) Clear Windows Event Logs
In the most progressed case, the operator used PsExec, Impacket-based tooling and Mimikatz for lateral movement and credential access before deploying a DragonForce ransomware binary
Subsequently, the attacker used Mimikatz to dump credential information (LSASS Memory, T1003.001) and collected Active Directory configuration...
a lot of these DragonForce incidents have been because of RDP and SSL-VPN account brute forcing.
one that begins with exploitation of the “CitrixBleed 2” vulnerability in Citrix NetScaler appliances... Huntress assesses with high confidence that the activity is the work of an initial access broker (IAB) weaponising CVE-2025-5777 to gain footholds in Citrix environments
...collected Active Directory configuration (Domain Trust Discovery, T1482) and network information (System Network Configuration Discovery, T1016) via ADFind and netscanold.exe.
Appendix C. MITRE ATT&CK ... (T1082) System Information Discovery
Before performing encryption, a directory traversal is conducted to identify files to be encrypted.
In the most progressed case, the operator used PsExec, Impacket-based tooling and Mimikatz for lateral movement and credential access
before deploying a DragonForce ransomware binary, resulting in encryption that Huntress says was contained to a single host through rapid triage
55 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
124 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group discussed as one of the major groups losing ground in Q2 2026, possibly due to affiliate attrition or retooling.
Ransomware used in the final stage of the intrusion chain after exploitation of CitrixBleed 2, with the attackers executing a DragonForce ransomware file that encrypted the affected environment.
Ransomware deployed at the end of the intrusion chain after Citrix NetScaler access, privilege escalation, persistence, and lateral movement; in the most progressed case it encrypted the victim environment.
Ransomware deployed at the end of the intrusion chain after Citrix NetScaler exploitation and post-compromise activity; in the observed case it encrypted a single host before containment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.