🇲🇾 DragonForce
Threat-actor battle card · maintained from public sources · last updated 2026-08-24 · also known as FireFlame, FuryStorm
CategoryRansomware cartel (RaaS)
AttributionOrigins in a former Malaysian hacktivist collective
First seenLate 2023
StatusActive
Rank#4
Victims L3M145
Victims YTD248
Primary targetsBusiness Services, Manufacturing, Construction, Technology, Healthcare, Retail, Government, Transportation
Overview
DragonForce is a Ransomware-as-a-Service operation that emerged in late 2023 — reportedly from a former Malaysian hacktivist group — and rebranded as a "ransomware cartel" on 19 March 2025, letting affiliates build their own brands on DragonForce tooling under a white-label model. Currently #4 with 248 claimed victims YTD 2026, 145 in the last 3 months. Closely associated with Scattered Spider, which has deployed DragonForce ransomware against high-profile UK retailers (Marks & Spencer, Co-op, Harrods — June 2025 campaign); two Scattered Spider members were sentenced in the UK on July 16, 2026 for the related 2024 TfL attack.
Q1 2026 activity: 101 victims posted — +29% vs Q4 2025. Pace accelerated sharply following RansomHub's collapse in April 2025, which drove a significant affiliate migration to DragonForce and Qilin. Average delay between attack and DLS listing: 21.3 days.
July 2026: Continued pace — new DLS claims include Edison Global Networks Limited (Hong Kong IT MSP, Jul 14), ATCOM Technology (telecom manufacturer, Jul 15); geographic expansion into APAC MSP/telecom targets observed alongside the established US/EU manufacturing base.
August 2026: Cumulative claimed victims reached 631 as of Aug 3 (ransomware.live, 43 in the trailing 30 days from that date). Sector expansion continues: R&D Machine and Engineering (aerospace/defense, US, DLS Aug 18) is the first documented aerospace/defense victim — a higher-sensitivity target class than the prior manufacturing base. Pace: consistent with H1 2026 trajectory.
Geographic distribution (all-time): United States 282, United Kingdom 42, Germany 32, Canada 20, Italy 18.
Sector distribution (all-time): Business Services 115, Manufacturing 100, Construction 59, Technology 58, Healthcare 37.
Tradecraft
- Multi-variant payloads built from leaked LockBit 3.0 and Conti builders — can switch families quickly to evade prediction.
- Dual extortion: encrypt + exfiltrate, leak on DLS.
- Cartel model: recruits affiliates and even other RaaS crews, sharing infrastructure for a cut.
- Backdoor.Turn / Teams C2 relay (June 2026, Symantec): affiliates abused Microsoft Teams' TURN relay protocol to tunnel C2 communications inside legitimate Teams traffic — the first confirmed use of the TURN relay as a covert C2 channel. The technique provides persistent, low-detection command-and-control inside enterprise environments where Teams is allowed. Dwell time in at least one confirmed intrusion was December 2025 — February 2026 before detection.
Notable victims
- Marks & Spencer, Co-op, Harrods — UK retail (June 2025, Scattered Spider-affiliated deployment)
- BITS Pilani — education/India (seen June 2026, DLS claim)
- Aptora — software/field service management/US (seen June 2026; databases of 100+ Aptora client companies alleged exfiltrated)
- Edison Global Networks Limited — IT MSP/Hong Kong (DLS July 14, 2026 🟥 unverified)
- ATCOM Technology — telecom manufacturer/Unknown (DLS July 15, 2026 🟥 unverified)
- R&D Machine and Engineering — aerospace/defense manufacturer/US (DLS Aug 18, 2026 🟥 unverified)
- Manufacturing and retail targets across EU/US DLS batches throughout 2025-2026
Assessment
The "cartel" structure and builder-agnostic payloads make DragonForce a moving target for signature-based defense. Its partnership with social-engineering crews like Scattered Spider raises the initial-access risk for large enterprises and their help desks. The confirmed Teams TURN relay C2 capability (June 2026 Symantec disclosure) is a significant TTPs escalation — defenders should inspect Teams relay traffic for anomalous C2 patterns and consider restricting external TURN relay sessions where possible. Post-RansomHub collapse affiliate migration has continued to increase DragonForce's operational tempo and victim volume through H1 2026. The July 2026 APAC listings (Hong Kong MSP, telecom manufacturer) suggest geographic expansion beyond the established US/EU/UK manufacturing base; MSP targeting raises supply-chain risk for downstream clients. The July 16 UK sentencing of two Scattered Spider members for TfL (which used DragonForce tooling) is the first law enforcement action directly linked to the Scattered Spider/DragonForce operational partnership. The August 2026 aerospace/defense listing (R&D Machine and Engineering) marks a sector shift into higher-sensitivity targets; aerospace/defense firms should verify data-loss exposure and treat DragonForce as a priority threat actor given the cartel's demonstrated reconnaissance depth and dwell time.
Sources
🗂️ Attacks & victims
All disclosed victims attributed to this actor, newest first.
August 2026
Aug 18
R&D Machine and Engineering
DragonForce
Ransomware · Aerospace & Defense · USA
DragonForce ransomware group posted R&D Machine and Engineering (rdmachine.com) on its DLS Aug 18; US aerospace and defense manufacturer; sensitive engineering data threatened for release. 🟥 Unverified DLS claim. · Sources: https://www.dexpose.io/dragonforce-strikes-r-d-machine-and-engineering/
Aug 13
GB Group S.A.
DragonForce
Ransomware · Unknown · Unknown
DragonForce DLS claim August 13, 2026; scope and country unconfirmed. · Sources: https://www.ransomware.live/group/dragonforce
July 2026
Jul 18
NewNet S.A.
DragonForce
Ransomware · IT services · CO
Colombian IT/business-services company claimed on DragonForce DLS July 18; no confirmation from organization · Sources: https://www.ransomware.live/group/dragonforce
Jul 15
ATCOM Technology
DragonForce
Ransomware · Telecommunications/Manufacturing · Unknown
Telecommunications manufacturer claimed on DragonForce DLS July 15. Country unconfirmed. No public statement. · Sources: https://www.ransomware.live/group/dragonforce
Jul 14
Asimar (Asian Marine Service PCL)
DragonForce
Ransomware · maritime · Thailand
Thailand's leading shipyard claimed on DragonForce DLS July 14; data type and volume unconfirmed · Sources: https://www.ransomware.live/group/dragonforce
Jul 14
Momenta
DragonForce
Ransomware · technology · CN
Chinese AI and autonomous-driving company claimed on DragonForce DLS July 14; group claims access to source code, financial documents, and configuration files; unconfirmed · Sources: https://www.ransomware.live/group/dragonforce
Jul 14
Edison Global Networks Limited
DragonForce
Ransomware · Technology/MSP · Hong Kong
Hong Kong-based IT systems integrator and MSP claimed on DragonForce DLS July 14; internal files alleged exfiltrated. No public statement. · Sources: https://www.hookphish.com/blog/ransomware-group-dragonforce-hits-edison-global-networks-limited/
Jul 13
Access Group International
DragonForce
Ransomware · business services · US
Business services company claimed on DragonForce DLS July 13; data type and volume unconfirmed · Sources: ransomware.live · purpleops.io
Jul 08
Ample Surveyor Services
DragonForce
Ransomware · land surveying · professional services/unknown region
DragonForce DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/dragonforce · Sources: [SharkStriker] · [ransomware.live]
Jul 08
HIVE360
DragonForce
Ransomware · HR · payroll services/UK
DragonForce DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/dragonforce · Sources: [SharkStriker] · [ransomware.live]
June 2026
Jun 30
Agroprime
DragonForce
Ransomware · agricultural technology SaaS · Brazil
developer of specialised SaaS software for automating agribusiness management and monitoring field personnel across Brazil; DragonForce DLS claim June 30, 2026; estimated attack date June 28, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/id/YWdyb3ByaW1lQGRyYWdvbmZvcmNl · https://www.breachsense.com/breaches/2026/june/ · Sources: [ransomware.live] · [Breachsense]
Jun 30
Hwa Seng Water Resources Biotech Co., Ltd.
DragonForce
Ransomware · beverage manufacturing · Taiwan
DragonForce DLS claim June 30, 2026; estimated attack date June 28, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/dragonforce · https://www.breachsense.com/breaches/2026/june/ · Sources: [ransomware.live] · [Breachsense]
Jun 29
STNI Co., Ltd.
DragonForce
Ransomware · virtual technology · South Korea
DragonForce DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/dragonforce-strikes-south-korean-virtual-tech-innovator-stni-co-ltd/ · https://www.ransomware.live/group/dragonforce · Sources: [DeXpose] · [ransomware.live]
Jun 27
Aptora
DragonForce
Ransomware · software · SaaS/field service management/US
field service management platform used by contractors and service businesses; DragonForce DLS claim June 27, 2026; attackers allege databases of 100+ Aptora client companies exfiltrated; data scope unconfirmed; 🟥 unverified · https://www.ransomware.live/group/dragonforce · Sources: [ransomware.live]
Jun 20
BITS Pilani
DragonForce
Ransomware · higher education · India
https://www.redpacketsecurity.com/dragonforce-ransomware-victim-bits-pilani-ac-in/ · https://www.ransomware.live/group/dragonforce · Sources: [RedPacket Security] · [ransomware.live]
Jun 14
INK
DragonForce
Ransomware · creative production · UK
UK-based production studio; 102.85 GB exfiltrated; DLS claim June 14, 2026; 7–8 day data-publication ultimatum issued after ransom deadline · https://www.dexpose.io/dragonforce-ransomware-attack-on-ink/ · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-ink/ · Sources: [DeXpose] · [RedPacket Security]
Jun 12
Al Shafar GRC
DragonForce
Ransomware · construction · UAE
UAE construction and governance, risk, and compliance services company; DragonForce DLS claim June 12, 2026; data scope and impact unconfirmed; previously uncaptured; 🟥 unverified · https://www.ransomware.live/group/dragonforce · https://www.dexpose.io/ · Sources: [ransomware.live] · [DeXpose]
Jun 12
Al Ishrak Contracting
DragonForce
Ransomware · construction · UAE
Dubai-based contracting company; DragonForce DLS claim June 12, 2026; data scope and impact unconfirmed; previously uncaptured; 🟥 unverified · https://www.ransomware.live/group/dragonforce · https://www.dexpose.io/ · Sources: [ransomware.live] · [DeXpose]
Jun 11
Areco
DragonForce
Ransomware · construction materials · Sweden
leading Swedish construction materials sector company; DLS claim June 11, 2026; data scope and impact unconfirmed · https://www.dexpose.io/dragonforce-ransomware-attack-on-areco/ · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-areco/ · Sources: [DeXpose] · [RedPacket Security]
Jun 10
Sayre Associates
DragonForce
Ransomware · civil engineering · land surveying/US
civil engineering and land surveying firm (est. 1969; land development, parks and recreation design, drainage/erosion control, construction administration); sensitive client data, project files, emails, and financial documents claimed; DLS claim June 10, 2026 · https://www.dexpose.io/dragonforce-strikes-sayre-associates-in-ransomware-attack/ · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-sayre-associates/ · Sources: [DeXpose] · [RedPacket Security]
Jun 05
REHA-ACTIV
DragonForce
Ransomware · healthcare · medical supply/Germany
medical rehabilitation equipment, mobility aids, orthotics, prosthetics, home care products; 48.55 GB exfiltrated; DLS claim June 5, 2026 · https://www.dexpose.io/dragonforce-targets-german-medical-supplier-reha-activ/ · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-reha-activ/ · Sources: [DeXpose] · [RedPacket Security]
Jun 03
Copamex
DragonForce
Ransomware · paper manufacturing · Mexico
Monterrey-based paper products manufacturer (est. 1928); DLS claim June 3, 2026; data scope unconfirmed · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-copamex/ · Sources: [RedPacket Security]
Jun 03
SETS Solutions
DragonForce
Ransomware · IT services · Lebanon
technology solutions provider (est. 1990; HR management system People365, data centre, cloud, end-user computing); DLS claim June 3, 2026; data scope unconfirmed · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-sets-solutions/ · Sources: [RedPacket Security]
Jun 01
Synex International Pvt Ltd
DragonForce
Ransomware · MEP systems · ELV solutions/solar energy/India
integrated mechanical, electrical, and plumbing (MEP), extra-low voltage (ELV), and solar energy solutions provider; DragonForce DLS claim June 1, 2026; 13.63 GB claimed; estimated attack date May 30, 2026 · https://www.dexpose.io/dragonforce-strikes-synex-international-pvt-ltd-in-sophisticated-ransomware-attack/ · https://www.hookphish.com/blog/ransomware-group-dragonforce-hits-synex-international-pvt-ltd/ · https://www.ransomware.live/id/U3luZXggSW50ZXJuYXRpb25hbCBQdnQgTHRkQGRyYWdvbmZvcmNl · Sources: [DeXpose] · [HookPhish] · [ransomware.live]
May 2026
May 27
QLS Group
DragonForce
Ransomware · retail · domestic appliances logistics/Australia
large Australian domestic appliances retailer and logistics group; DragonForce DLS claim May 27, 2026; threat to release data; data scope unconfirmed; 🟥 unverified · https://www.dexpose.io/dragonforce-targets-qls-group-in-ransomware-attack/ · https://www.ransomware.live/group/dragonforce · Sources: [DeXpose] · [ransomware.live]
April 2026
Apr 16
Empower Group
DragonForce
Ransomware · financial services · UAE
UAE financial services firm; DragonForce DLS claim April 16, 2026; 316.38 GB exfiltrated claimed; data scope unconfirmed; previously uncaptured; 🟥 unverified · https://www.ransomware.live/group/dragonforce · https://www.dexpose.io/ · Sources: [ransomware.live] · [DeXpose]
May 2025
May 01
Harrods
DragonForce
Ransomware · retail · UK
third UK retailer hit; attack confirmed 1 May 2025, access restricted to contain it · https://www.acronis.com/en/blog/posts/the-harrods-cyberattacks-a-legendary-retailer-becomes-a-target/ · https://www.picussecurity.com/resource/blog/dragonforce-ransomware-attacks-retail-giants · Sources: [Acronis] · [Picus]
April 2025
Apr 30
Co-op
DragonForce
Ransomware · retail · UK
back-office & call-centre disruption; 10,000+ members' personal data exposed · https://www.infosecurity-magazine.com/news/dragonforce-goup-ms-coop-harrods/ · Sources: [Infosecurity]
Apr 22
Marks & Spencer
DragonForce
Ransomware · retail · UK
~£300M profit hit; online orders & payments disrupted for weeks; customer + employee data threatened (Scattered Spider service-desk initial access) · https://www.blackfog.com/marks-and-spencer-ransomware-attack/ · https://www.infosecurity-magazine.com/news/dragonforce-goup-ms-coop-harrods/ · Sources: [BlackFog] · [Infosecurity]
← All threat actors · Full victim database →