Overview
Platforms:
Linux · NAS · VMware ESXi · Windows
Variants:
LockBit-derived · Conti-derived
Extensions:
.dragonforce_encrypted
ATT&CK software:
—
Initial access:
Exploit Public-Facing Application · Valid Accounts · Phishing · External Remote Services
Top countries:
US · GB · AE · CA
Observed sectors:
Manufacturing · Construction · Technology · Professional Services · Healthcare
Tracked victims:
650
Attribution
Relationships
GOLD HARVEST / Scattered Spider
UNCONFIRMED
Reported relationship
Microsoft observed Octo Tempest / Scattered Spider deploying DragonForce ransomware, particularly against VMware ESX environments. The broader organizational relationship remains loosely defined, so it is retained as a probable affiliate relationship rather than a formal operator attribution.
RansomHub
UNCONFIRMED
Reported relationship
DragonForce publicly suggested collaboration with RansomHub during its 2025 cartel expansion, while subsequent reporting documented open conflict and indications of a hostile takeover. The relationship is therefore treated as disputed rather than an affiliate link.
Affiliates
GOLD HARVEST / Scattered Spider
Reported affiliate activity involving DragonForce ransomware deployment.
First seen:
May 2025
Activity
Initial Access
CitrixBleed 2 exploitation
Huntress observed an intrusion cluster exploiting CVE-2025-5777 against Citrix NetScaler systems, with DragonForce ransomware deployed in the most advanced observed case.
Social engineering
DragonForce-associated affiliate activity has been publicly linked to social-engineering techniques targeting enterprise users and help desks.
Phishing, stolen credentials and exposed services
DragonForce-related intrusions have used phishing, exploitation of known vulnerabilities, leaked or stolen credentials, RDP and VPN weaknesses for initial access.
SimpleHelp RMM exploitation
Sophos MDR investigated an MSP compromise in which attackers used access through SimpleHelp to deploy DragonForce ransomware across multiple endpoints. Sophos assessed the vulnerability chain with medium confidence.
Social engineering by DragonForce-associated affiliates
Microsoft documented Octo Tempest activity using help-desk impersonation, password resets and other social-engineering techniques in attack chains that later deployed DragonForce.
Recent Observations
Continued victim publication
September 2026
Leak-site activity
New DragonForce victim claims continued to be published in September 2026.
CitrixBleed 2 intrusion chain
July 2026
Intrusion activity
Huntress documented a standardized intrusion chain involving CitrixBleed 2 exploitation, privilege escalation, remote-management tooling and DragonForce ransomware deployment.
CitrixBleed 2 deployment chain
July 2026
Intrusion activity
Huntress documented repeated Citrix NetScaler intrusion activity in which CVE-2025-5777 exploitation led through privilege escalation and remote-access tooling to DragonForce deployment.
Octo Tempest deploys DragonForce against ESXi
July 2025
Affiliate activity
Microsoft observed Octo Tempest deploying DragonForce ransomware with a particular focus on VMware ESX hypervisor environments.
SimpleHelp MSP compromise
June 2025
Intrusion activity
Sophos MDR investigated an MSP compromise involving SimpleHelp access, data exfiltration and DragonForce deployment across multiple endpoints.
DragonForce cartel model announced
March 2025
Operational change
DragonForce announced a distributed white-label model allowing affiliates to use its ransomware infrastructure and tooling while operating under independent branding.
TTPs
ATT&CK coverage:
11 techniques
· 10 tactics
T1190
Exploit Public-Facing Application
VERIFIEDInitial Access
DragonForce-related intrusions have exploited public-facing Citrix NetScaler, Ivanti and other exposed infrastructure.
T1078
Valid Accounts
VERIFIEDInitial Access / Persistence
Leaked or stolen credentials and authenticated access have been used in DragonForce-related intrusion activity.
T1136.001
Create Account: Local Account
VERIFIEDPersistence
Operators created rogue local administrator accounts during observed DragonForce-related intrusion activity.
Show more TTPs (8)
T1219
Remote Access Software
VERIFIEDCommand and Control
Remote-management tooling including ScreenConnect and Zoho Assist was observed in DragonForce deployment chains.
T1021.001
Remote Desktop Protocol
VERIFIEDLateral Movement
RDP was used for interactive access after creation of administrator accounts.
T1569.002
Service Execution
VERIFIEDExecution
PsExec and related remote-execution techniques were observed during lateral movement.
T1003
OS Credential Dumping
VERIFIEDCredential Access
Mimikatz and credential-dumping activity have been documented in DragonForce-associated intrusions.
T1486
Data Encrypted for Impact
VERIFIEDImpact
DragonForce encrypts victim systems; Microsoft and CISA specifically documented deployments affecting VMware ESXi.
T1567.002
Exfiltration to Cloud Storage
VERIFIEDExfiltration
DragonForce operators have used MEGA as one method for data exfiltration.
T1566
Phishing
VERIFIEDInitial Access
Phishing email is documented as an initial-access method in DragonForce-related intrusions.
T1133
External Remote Services
VERIFIEDPersistence / Initial Access
DragonForce operators have targeted RDP services and VPN weaknesses to obtain or maintain remote access.
Victims
Medical Department Store
CLAIMED
rubbermill.com
CLAIMED
Homewood Sales
CLAIMED
Norwood Law Firm
CLAIMED
Frato
CLAIMED
Show more victims (5)
Criba
CLAIMED
Brookview Financial
CLAIMED
Wozair
CLAIMED
Hogan Omidi P.C.
CLAIMED
R & D Machine and Engineering
CLAIMED
CVEs
Citrix
— NetScaler ADC / NetScaler Gateway
Huntress observed exploitation in an intrusion cluster that culminated in DragonForce deployment.
Associated since:
January 2026
Apache
— Log4j
SentinelOne lists Log4Shell among vulnerabilities specifically associated with past DragonForce intrusions.
Associated since:
May 2025
Ivanti
— Connect Secure / Policy Secure
Authentication bypass associated with past DragonForce intrusions in SentinelOne reporting.
Associated since:
May 2025
Show more CVEs (6)
Microsoft
— Windows SmartScreen
Security-feature bypass associated with past DragonForce intrusions in SentinelOne reporting.
Associated since:
May 2025
Ivanti
— Connect Secure / Policy Secure
Command-injection vulnerability associated with past DragonForce intrusions.
Associated since:
May 2025
Ivanti
— Connect Secure / Policy Secure
Path-traversal vulnerability associated with past DragonForce intrusions.
Associated since:
May 2025
SimpleHelp
— SimpleHelp RMM
Sophos MDR assessed with medium confidence that attackers exploited this path-traversal vulnerability before deploying DragonForce.
Associated since:
June 2025
SimpleHelp
— SimpleHelp RMM
Sophos MDR assessed with medium confidence that this arbitrary file-upload vulnerability formed part of the pre-DragonForce SimpleHelp exploit chain.
Associated since:
June 2025
SimpleHelp
— SimpleHelp RMM
Sophos MDR assessed with medium confidence that this privilege escalation vulnerability formed part of the SimpleHelp chain.
Associated since:
June 2025
Infrastructure
Leak / news site
Tor-based DragonForce leak and publication infrastructure
ONLINE
Last checked:
September 15, 2026
Negotiation portal
Tor-based DragonForce negotiation infrastructure
Contact channel
Tox
Timeline
2026-09
Continued activity
DragonForce continued publishing new victim claims in September 2026.
2026-09
Continued leak-site activity
DragonForce continued publishing victim claims and operating Tor-based public infrastructure in September 2026.
2026-07
CitrixBleed 2 deployment chain
Huntress documented a repeated intrusion chain using CVE-2025-5777 that culminated in DragonForce ransomware deployment.
Show more events (6)
2025-07
Octo Tempest DragonForce deployment documented
Microsoft reported observed Octo Tempest deployment of DragonForce with particular focus on VMware ESX environments.
2025-06
SimpleHelp deployment chain documented
Sophos MDR investigated an MSP compromise involving SimpleHelp, data theft and DragonForce ransomware deployment.
2025-05
UK retail activity
DragonForce ransomware was publicly associated with high-profile cyberattacks affecting major UK retailers.
2025-05
Rival leak sites targeted
DragonForce was linked to defacement activity affecting BlackLock and Mamona leak sites during its cartel expansion.
2025-03
Cartel model announced
DragonForce announced a distributed white-label affiliate model on March 19, 2025.
2023-08
DragonForce emerges
DragonForce emerged as a ransomware-as-a-service operation.
Sources
Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines
Google Threat Intelligence Group
Vendor research
Show more sources (8)
DragonForce Ransomware Gang: From Hacktivists to High Street Extortionists
SentinelOne
Vendor research