Skip to content

🇲🇾 DragonForce

Threat-actor battle card · maintained from public sources · last updated 2026-08-24 · also known as FireFlame, FuryStorm

CategoryRansomware cartel (RaaS)
AttributionOrigins in a former Malaysian hacktivist collective
First seenLate 2023
StatusActive
Rank#4
Victims L3M145
Victims YTD248
Primary targetsBusiness Services, Manufacturing, Construction, Technology, Healthcare, Retail, Government, Transportation

Overview

DragonForce is a Ransomware-as-a-Service operation that emerged in late 2023 — reportedly from a former Malaysian hacktivist group — and rebranded as a "ransomware cartel" on 19 March 2025, letting affiliates build their own brands on DragonForce tooling under a white-label model. Currently #4 with 248 claimed victims YTD 2026, 145 in the last 3 months. Closely associated with Scattered Spider, which has deployed DragonForce ransomware against high-profile UK retailers (Marks & Spencer, Co-op, Harrods — June 2025 campaign); two Scattered Spider members were sentenced in the UK on July 16, 2026 for the related 2024 TfL attack.

Q1 2026 activity: 101 victims posted — +29% vs Q4 2025. Pace accelerated sharply following RansomHub's collapse in April 2025, which drove a significant affiliate migration to DragonForce and Qilin. Average delay between attack and DLS listing: 21.3 days.

July 2026: Continued pace — new DLS claims include Edison Global Networks Limited (Hong Kong IT MSP, Jul 14), ATCOM Technology (telecom manufacturer, Jul 15); geographic expansion into APAC MSP/telecom targets observed alongside the established US/EU manufacturing base.

August 2026: Cumulative claimed victims reached 631 as of Aug 3 (ransomware.live, 43 in the trailing 30 days from that date). Sector expansion continues: R&D Machine and Engineering (aerospace/defense, US, DLS Aug 18) is the first documented aerospace/defense victim — a higher-sensitivity target class than the prior manufacturing base. Pace: consistent with H1 2026 trajectory.

Geographic distribution (all-time): United States 282, United Kingdom 42, Germany 32, Canada 20, Italy 18.

Sector distribution (all-time): Business Services 115, Manufacturing 100, Construction 59, Technology 58, Healthcare 37.

Tradecraft

  • Multi-variant payloads built from leaked LockBit 3.0 and Conti builders — can switch families quickly to evade prediction.
  • Dual extortion: encrypt + exfiltrate, leak on DLS.
  • Cartel model: recruits affiliates and even other RaaS crews, sharing infrastructure for a cut.
  • Backdoor.Turn / Teams C2 relay (June 2026, Symantec): affiliates abused Microsoft Teams' TURN relay protocol to tunnel C2 communications inside legitimate Teams traffic — the first confirmed use of the TURN relay as a covert C2 channel. The technique provides persistent, low-detection command-and-control inside enterprise environments where Teams is allowed. Dwell time in at least one confirmed intrusion was December 2025 — February 2026 before detection.

Notable victims

  • Marks & Spencer, Co-op, Harrods — UK retail (June 2025, Scattered Spider-affiliated deployment)
  • BITS Pilani — education/India (seen June 2026, DLS claim)
  • Aptora — software/field service management/US (seen June 2026; databases of 100+ Aptora client companies alleged exfiltrated)
  • Edison Global Networks Limited — IT MSP/Hong Kong (DLS July 14, 2026 🟥 unverified)
  • ATCOM Technology — telecom manufacturer/Unknown (DLS July 15, 2026 🟥 unverified)
  • R&D Machine and Engineering — aerospace/defense manufacturer/US (DLS Aug 18, 2026 🟥 unverified)
  • Manufacturing and retail targets across EU/US DLS batches throughout 2025-2026

Assessment

The "cartel" structure and builder-agnostic payloads make DragonForce a moving target for signature-based defense. Its partnership with social-engineering crews like Scattered Spider raises the initial-access risk for large enterprises and their help desks. The confirmed Teams TURN relay C2 capability (June 2026 Symantec disclosure) is a significant TTPs escalation — defenders should inspect Teams relay traffic for anomalous C2 patterns and consider restricting external TURN relay sessions where possible. Post-RansomHub collapse affiliate migration has continued to increase DragonForce's operational tempo and victim volume through H1 2026. The July 2026 APAC listings (Hong Kong MSP, telecom manufacturer) suggest geographic expansion beyond the established US/EU/UK manufacturing base; MSP targeting raises supply-chain risk for downstream clients. The July 16 UK sentencing of two Scattered Spider members for TfL (which used DragonForce tooling) is the first law enforcement action directly linked to the Scattered Spider/DragonForce operational partnership. The August 2026 aerospace/defense listing (R&D Machine and Engineering) marks a sector shift into higher-sensitivity targets; aerospace/defense firms should verify data-loss exposure and treat DragonForce as a priority threat actor given the cartel's demonstrated reconnaissance depth and dwell time.

Sources

🗂️ Attacks & victims

All disclosed victims attributed to this actor, newest first.

August 2026

Aug 18 R&D Machine and Engineering DragonForce Ransomware · Aerospace & Defense · USA DragonForce ransomware group posted R&D Machine and Engineering (rdmachine.com) on its DLS Aug 18; US aerospace and defense manufacturer; sensitive engineering data threatened for release. 🟥 Unverified DLS claim. · Sources: https://www.dexpose.io/dragonforce-strikes-r-d-machine-and-engineering/
Aug 13 GB Group S.A. DragonForce Ransomware · Unknown · Unknown DragonForce DLS claim August 13, 2026; scope and country unconfirmed. · Sources: https://www.ransomware.live/group/dragonforce

July 2026

Jul 18 NewNet S.A. DragonForce Ransomware · IT services · CO Colombian IT/business-services company claimed on DragonForce DLS July 18; no confirmation from organization · Sources: https://www.ransomware.live/group/dragonforce
Jul 15 ATCOM Technology DragonForce Ransomware · Telecommunications/Manufacturing · Unknown Telecommunications manufacturer claimed on DragonForce DLS July 15. Country unconfirmed. No public statement. · Sources: https://www.ransomware.live/group/dragonforce
Jul 14 Asimar (Asian Marine Service PCL) DragonForce Ransomware · maritime · Thailand Thailand's leading shipyard claimed on DragonForce DLS July 14; data type and volume unconfirmed · Sources: https://www.ransomware.live/group/dragonforce
Jul 14 Momenta DragonForce Ransomware · technology · CN Chinese AI and autonomous-driving company claimed on DragonForce DLS July 14; group claims access to source code, financial documents, and configuration files; unconfirmed · Sources: https://www.ransomware.live/group/dragonforce
Jul 14 Edison Global Networks Limited DragonForce Ransomware · Technology/MSP · Hong Kong Hong Kong-based IT systems integrator and MSP claimed on DragonForce DLS July 14; internal files alleged exfiltrated. No public statement. · Sources: https://www.hookphish.com/blog/ransomware-group-dragonforce-hits-edison-global-networks-limited/
Jul 13 Access Group International DragonForce Ransomware · business services · US Business services company claimed on DragonForce DLS July 13; data type and volume unconfirmed · Sources: ransomware.live · purpleops.io
Jul 08 Ample Surveyor Services DragonForce Ransomware · land surveying · professional services/unknown region DragonForce DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/dragonforce · Sources: [SharkStriker] · [ransomware.live]
Jul 08 HIVE360 DragonForce Ransomware · HR · payroll services/UK DragonForce DLS claim July 8, 2026; data scope and impact unconfirmed; 🟥 unverified · https://sharkstriker.com/blog/ransomware-roundup/ · https://www.ransomware.live/group/dragonforce · Sources: [SharkStriker] · [ransomware.live]

June 2026

Jun 30 Agroprime DragonForce Ransomware · agricultural technology SaaS · Brazil developer of specialised SaaS software for automating agribusiness management and monitoring field personnel across Brazil; DragonForce DLS claim June 30, 2026; estimated attack date June 28, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/id/YWdyb3ByaW1lQGRyYWdvbmZvcmNl · https://www.breachsense.com/breaches/2026/june/ · Sources: [ransomware.live] · [Breachsense]
Jun 30 Hwa Seng Water Resources Biotech Co., Ltd. DragonForce Ransomware · beverage manufacturing · Taiwan DragonForce DLS claim June 30, 2026; estimated attack date June 28, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/dragonforce · https://www.breachsense.com/breaches/2026/june/ · Sources: [ransomware.live] · [Breachsense]
Jun 29 STNI Co., Ltd. DragonForce Ransomware · virtual technology · South Korea DragonForce DLS claim June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/dragonforce-strikes-south-korean-virtual-tech-innovator-stni-co-ltd/ · https://www.ransomware.live/group/dragonforce · Sources: [DeXpose] · [ransomware.live]
Jun 27 Aptora DragonForce Ransomware · software · SaaS/field service management/US field service management platform used by contractors and service businesses; DragonForce DLS claim June 27, 2026; attackers allege databases of 100+ Aptora client companies exfiltrated; data scope unconfirmed; 🟥 unverified · https://www.ransomware.live/group/dragonforce · Sources: [ransomware.live]
Jun 20 BITS Pilani DragonForce Ransomware · higher education · India https://www.redpacketsecurity.com/dragonforce-ransomware-victim-bits-pilani-ac-in/ · https://www.ransomware.live/group/dragonforce · Sources: [RedPacket Security] · [ransomware.live]
Jun 14 INK DragonForce Ransomware · creative production · UK UK-based production studio; 102.85 GB exfiltrated; DLS claim June 14, 2026; 7–8 day data-publication ultimatum issued after ransom deadline · https://www.dexpose.io/dragonforce-ransomware-attack-on-ink/ · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-ink/ · Sources: [DeXpose] · [RedPacket Security]
Jun 12 Al Shafar GRC DragonForce Ransomware · construction · UAE UAE construction and governance, risk, and compliance services company; DragonForce DLS claim June 12, 2026; data scope and impact unconfirmed; previously uncaptured; 🟥 unverified · https://www.ransomware.live/group/dragonforce · https://www.dexpose.io/ · Sources: [ransomware.live] · [DeXpose]
Jun 12 Al Ishrak Contracting DragonForce Ransomware · construction · UAE Dubai-based contracting company; DragonForce DLS claim June 12, 2026; data scope and impact unconfirmed; previously uncaptured; 🟥 unverified · https://www.ransomware.live/group/dragonforce · https://www.dexpose.io/ · Sources: [ransomware.live] · [DeXpose]
Jun 11 Areco DragonForce Ransomware · construction materials · Sweden leading Swedish construction materials sector company; DLS claim June 11, 2026; data scope and impact unconfirmed · https://www.dexpose.io/dragonforce-ransomware-attack-on-areco/ · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-areco/ · Sources: [DeXpose] · [RedPacket Security]
Jun 10 Sayre Associates DragonForce Ransomware · civil engineering · land surveying/US civil engineering and land surveying firm (est. 1969; land development, parks and recreation design, drainage/erosion control, construction administration); sensitive client data, project files, emails, and financial documents claimed; DLS claim June 10, 2026 · https://www.dexpose.io/dragonforce-strikes-sayre-associates-in-ransomware-attack/ · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-sayre-associates/ · Sources: [DeXpose] · [RedPacket Security]
Jun 05 REHA-ACTIV DragonForce Ransomware · healthcare · medical supply/Germany medical rehabilitation equipment, mobility aids, orthotics, prosthetics, home care products; 48.55 GB exfiltrated; DLS claim June 5, 2026 · https://www.dexpose.io/dragonforce-targets-german-medical-supplier-reha-activ/ · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-reha-activ/ · Sources: [DeXpose] · [RedPacket Security]
Jun 03 Copamex DragonForce Ransomware · paper manufacturing · Mexico Monterrey-based paper products manufacturer (est. 1928); DLS claim June 3, 2026; data scope unconfirmed · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-copamex/ · Sources: [RedPacket Security]
Jun 03 SETS Solutions DragonForce Ransomware · IT services · Lebanon technology solutions provider (est. 1990; HR management system People365, data centre, cloud, end-user computing); DLS claim June 3, 2026; data scope unconfirmed · https://www.redpacketsecurity.com/dragonforce-ransomware-victim-sets-solutions/ · Sources: [RedPacket Security]
Jun 01 Synex International Pvt Ltd DragonForce Ransomware · MEP systems · ELV solutions/solar energy/India integrated mechanical, electrical, and plumbing (MEP), extra-low voltage (ELV), and solar energy solutions provider; DragonForce DLS claim June 1, 2026; 13.63 GB claimed; estimated attack date May 30, 2026 · https://www.dexpose.io/dragonforce-strikes-synex-international-pvt-ltd-in-sophisticated-ransomware-attack/ · https://www.hookphish.com/blog/ransomware-group-dragonforce-hits-synex-international-pvt-ltd/ · https://www.ransomware.live/id/U3luZXggSW50ZXJuYXRpb25hbCBQdnQgTHRkQGRyYWdvbmZvcmNl · Sources: [DeXpose] · [HookPhish] · [ransomware.live]

May 2026

May 27 QLS Group DragonForce Ransomware · retail · domestic appliances logistics/Australia large Australian domestic appliances retailer and logistics group; DragonForce DLS claim May 27, 2026; threat to release data; data scope unconfirmed; 🟥 unverified · https://www.dexpose.io/dragonforce-targets-qls-group-in-ransomware-attack/ · https://www.ransomware.live/group/dragonforce · Sources: [DeXpose] · [ransomware.live]

April 2026

Apr 16 Empower Group DragonForce Ransomware · financial services · UAE UAE financial services firm; DragonForce DLS claim April 16, 2026; 316.38 GB exfiltrated claimed; data scope unconfirmed; previously uncaptured; 🟥 unverified · https://www.ransomware.live/group/dragonforce · https://www.dexpose.io/ · Sources: [ransomware.live] · [DeXpose]

May 2025

May 01 Harrods DragonForce Ransomware · retail · UK third UK retailer hit; attack confirmed 1 May 2025, access restricted to contain it · https://www.acronis.com/en/blog/posts/the-harrods-cyberattacks-a-legendary-retailer-becomes-a-target/ · https://www.picussecurity.com/resource/blog/dragonforce-ransomware-attacks-retail-giants · Sources: [Acronis] · [Picus]

April 2025

Apr 30 Co-op DragonForce Ransomware · retail · UK back-office & call-centre disruption; 10,000+ members' personal data exposed · https://www.infosecurity-magazine.com/news/dragonforce-goup-ms-coop-harrods/ · Sources: [Infosecurity]
Apr 22 Marks & Spencer DragonForce Ransomware · retail · UK ~£300M profit hit; online orders & payments disrupted for weeks; customer + employee data threatened (Scattered Spider service-desk initial access) · https://www.blackfog.com/marks-and-spencer-ransomware-attack/ · https://www.infosecurity-magazine.com/news/dragonforce-goup-ms-coop-harrods/ · Sources: [BlackFog] · [Infosecurity]

← All threat actors · Full victim database →