DragonForce Ransomware Group Targets 363 Companies in Strategic Expansion Since 2023

DragonForce emerged as a significant ransomware threat in December 2023, operating as a Ransomware-as-a-Service (RaaS) provider that promotes itself as a cartel to attract affiliates and expand operations.

The group quickly scaled its attacks, listing 363 victims on its Data Leak Site (DLS) by January 2026, with activity peaking at 35 victims in December 2025.

Drawing from leaked LockBit 3.0 and Conti source code, DragonForce offers customized payloads via its RansomBay service, enabling affiliates to generate builds for Windows and Linux environments.

DragonForce posted its first victim on December 6, 2023, with 22 disclosures that month, before steadily increasing its targets across sectors such as manufacturing, retail, IT, and construction.

A post uploaded to BreachForums by the user @dragonforce (Source: medium)
A post uploaded to BreachForums by the user @dragonforce (Source: medium)

The US faced the most attacks, followed by the UK, Germany, Australia, and Italy, often hitting high-profile retailers and supply-chain providers in 2025.

Affiliates receive 80% of ransoms, using double extortion encrypting files and leaking data if unpaid while the group avoids healthcare per a self-imposed code.

The group maintains a strong dark web presence on BreachForums, RAMP, and Exploit, advertising RaaS services, recruiting pentesters, and offering unique features like harassment calling and data analysis.

DragonForce differentiates by targeting rivals, such as defacing BlackLock’s site and claiming RansomHub’s infrastructure after it went offline in April 2025.

The DragonForce data leak site (DLS) (Source: medium)
The DragonForce data leak site (DLS) (Source: medium)

It has sought alliances with LockBit and Qilin, positioning itself as a cartel leader with white-label options for affiliates to rebrand payloads.

Technical Profile and Binary Details

DragonForce’s affiliate panel supports client management, lead generation, team coordination, content publishing, and tickets. It has evolved since Group-IB’s 2024 analysis by removing exposed LockBit builders while retaining BYOVD for process termination.

Windows binaries use ChaCha8 for configuration decryption and file encryption, appending 537 bytes of metadata (the expanded Encryption Ratio field) and supporting extension-based modes such as full, partial, or header encryption.

Monthly attack trends of the DragonForce group (Source: medium)
Monthly attack trends of the DragonForce group (Source: medium)

Linux variants target ESXi, NAS, and RHEL, running as daemons with VM shutdowns on ESXi, system info collection, and MOTD modifications post-encryption.

Default configs exclude paths and apply user-defined encryption, with beta extensions for per-file overrides. As of January 2026, the LockBit 3.0-based builder has been discontinued, but core functions remain.

According to Medium, associated groups include BlackLock, RansomHub, Scattered Spider, DEVMAN, and LockBit, linked via code similarities, shared infrastructure, or conflicts.

Organizations should patch vulnerabilities like CVE-2021-44228, monitor for BYOVD, and scan for DragonForce IOCs on leak sites.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories