← All briefs
critical June 11, 2026

DragonForce Ransomware Cartel: Multi-Sector Targeting with Dual-Platform Encryption

Source report →

DragonForce is a ransomware-as-a-service group first observed in August 2023 that evolved into a cartel model in March 2025, operating as an umbrella organization where other ransomware brands run under shared infrastructure, including negotiation portals, leak sites, and encryptor tooling, in exchange for up to 80 percent of ransom proceeds. The group has shown a deliberate push toward high-profile entities and supply-chain service providers to maximize leverage through victim visibility and downstream impact, a strategy that drew significant attention through a series of UK retail attacks in 2025 in which Scattered Spider served as an initial access broker. In August 2025 the group further lowered the affiliate barrier by introducing a fee-based service providing extortion scripts and management letters for targets with annual revenues above $15 million.

Affiliates gain initial access by exploiting unpatched internet-facing appliances, with documented targeting of Ivanti Connect Secure and SimpleHelp RMM vulnerabilities, as well as Log4Shell and valid compromised accounts. Once inside, Mimikatz and LaZagne are used to harvest credentials from LSASS memory and SAM registry hives, and AdFind maps the domain before privilege escalation and lateral movement over RDP and PsExec begin.

Defense evasion relies on bring-your-own-vulnerable-driver techniques, using tools like PCHunter and ProcessHacker to disable endpoint protection at the kernel level, alongside registry modifications that disable Windows Defender. Data is staged and exfiltrated to MEGA.nz before the encryption phase, which begins with Volume Shadow Copy deletion and boot recovery changes via bcdedit. Separate encryptors are then deployed for Windows and Linux/ESXi environments, with the ESXi variant targeting virtual machine storage under /vmfs/volumes.

SHA256 FILE HASH 18
0023baf38263857e32b8cdbeb25ac2e95ae25ccf082d193f187ef8fc192f930b
1250ba6f25fd60077f698a2617c15f89d58c1867339bfd9ee8ab19ce9943304b
312ca1a8e35dcf5b80b1526948bd1081fed2293b31d061635e9f048f3fe5eb83
372e753992d2a95895f88d132af89d13e2dd3742403a25471b070106b6c5a183
3a6ea4790be64a6ef48782cafc951a75d4b16508ace61eeab10358fb687ce0fb
527f71e2ac55ee18f4376f213a242a20aa63f7ab501a23888b7d41ea8661802b
5c54bd1aa2abf024f53490b7d93101496b5842a5a81a51955fe7f1d5e4281409
61fa5321c70325a6986c965144198f3cf25b32dd321c9517120357ea2fa147a7
6d8d24b3db2d53ca3968d39cfa575cdca5d0fcb294c54abafb7f3ba82c71db4c
88169b1d4778ed6c5fda97375efb5b9171ea52649c8715bb449801c39bce4ad4
d4de7d7990114c51056afeedb827d880549d5761aac6bdef0f14cb17c25103b3
de26ea9b30858a588447c8f65f27d53e88da6dfbbe0a635dc723d1fd896ae628
188bc243cc42f8ffa4c1ed02aad5a76c9000e3d58104f45fe71af66536a274da
4194a2c45d940078a178de9288e3ef87d267c26964f1fd975afcee0c447beed3
4d0650b3fe7a87c894c5478d32d2d48bd70a0134f1787c4a1e68c28436841798
55befb5de5d9bc45978efd1a960ae21ed81e4be9c6521aaeebf8d5884444e3c9
572d88c419c6ae75aeb784ceab327d040cb589903d6285bbffa77338111af14b
df903c620508011ca8eb2aaaf9712a526b31a12c800b856cd524ebb3fde854b2

Detections (10)

Enable detections →

Connect your environment for suggestions and queries personalized to your security telemetry.

  • Identification of Mimikatz Execution & Artifacts
  • Process Connection to MEGA Domain
  • PSExec Execution
  • Cobalt Strike Service Installations Detection
  • Windows Defender Tampering in Registry via reg.exe
  • Boot Configuration Tampering Via Bcdedit.EXE
  • Known Vulnerable Driver Load (BYOVD)
  • Safe-Mode Reboot Staged for Encryption Evasion
  • ESXi VM Enumeration and Shutdown via vim-cmd