Multiple reports detailed emerging and evolving ransomware operations and the tactics they use to scale. DragonForce has positioned itself as a “cartel”-style Ransomware-as-a-Service (RaaS) operation, using dark web forums (e.g., BreachForums, RAMP, Exploit) for recruitment and promotion, and advertising capabilities such as a payload builder (“RansomBay”) and victim-pressure services (including harassment calls). Separate profiling described The Gentlemen as an emerging double-extortion ransomware group first clearly observed in active campaigns in 2025, with a Go-based locker supporting Windows, Linux, and ESXi, and an operator-controlled execution model that requires a password parameter.
Additional research reported Gunra as a RaaS operation with a newly launched affiliate program advertised on dark web forums in January 2026; researchers claimed access to affiliate-panel credentials and obtained a live sample for technical analysis, describing configurable attack parameters, selective encryption, and path exclusions to preserve system operability for payment. Separately, analysis of the Reynolds ransomware family highlighted built-in BYOVD defense evasion, bundling a vulnerable NsecSoft NSecKrnl driver within the ransomware payload to disable EDR—an approach that reduces the need for a separate pre-ransomware EDR-killer stage and reflects continued innovation in endpoint security bypass techniques.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
SOCRadar published a profile in February 2026 describing The Gentlemen's campaigns across at least 17 countries and multiple sectors, with victim claims continuing into January 2026. The profile also summarized the group's attack chain, tooling, and recommended mitigations.
By February 2026, S2W reported that DragonForce had targeted 363 companies between December 2023 and January 2026. The reporting also described updated Windows ransomware metadata, ChaCha8-based configuration decryption, and a beta feature for extension-based encryption rules.
After engaging via the Tox contact in the Gunra advertisement, CloudSEK researchers said they infiltrated the program, obtained a PDF guide, gained access to the RaaS management panel, and retrieved a live ransomware sample. This enabled a technical analysis of the locker's encryption, exclusions, ransom note, and execution behavior.
In January 2026, Gunra's affiliate program was advertised on the Ramp Forum. The advertisement promoted cross-platform targeting across Windows, Linux, ESXi, and NAS systems on both x86 and ARM architectures.
DragonForce's activity peaked in December 2025, when 35 victims were posted in a single month. This reflected a major escalation within a campaign that reportedly hit 363 companies from late 2023 through January 2026.
In September 2025, a dark web post advertised The Gentlemen's ransomware-as-a-service program. The post described a 90% affiliate payout, centralized operator-controlled infrastructure, and support for Windows, Linux, and ESXi targets.
The Gentlemen was first observed conducting active ransomware campaigns in August 2025. The group quickly showed a mature double-extortion model and cross-platform targeting.
Researchers first observed Gunra ransomware activity in May 2025, marking the emergence of the operation before its later affiliate recruitment push. This is the earliest reported activity tied to the Gunra group in the references.
DragonForce began operating as a ransomware-as-a-service operation in December 2023. It later promoted itself on dark web forums and developed a broader affiliate-driven model.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesocradar.io
Open sourcecloudsek.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.