Overview

Platforms: Linux · NAS · VMware ESXi · Windows
Variants: LockBit-derived · Conti-derived
Extensions: .dragonforce_encrypted
ATT&CK software: —
Initial access: Exploit Public-Facing Application · Valid Accounts · Phishing · External Remote Services
Top countries: US · GB · AE · CA
Observed sectors: Manufacturing · Construction · Technology · Professional Services · Healthcare
Tracked victims: 650

Attribution

Relationships

GOLD HARVEST / Scattered Spider UNCONFIRMED
Reported relationship
Microsoft observed Octo Tempest / Scattered Spider deploying DragonForce ransomware, particularly against VMware ESX environments. The broader organizational relationship remains loosely defined, so it is retained as a probable affiliate relationship rather than a formal operator attribution.
RansomHub UNCONFIRMED
Reported relationship
DragonForce publicly suggested collaboration with RansomHub during its 2025 cartel expansion, while subsequent reporting documented open conflict and indications of a hostile takeover. The relationship is therefore treated as disputed rather than an affiliate link.

Affiliates

GOLD HARVEST / Scattered Spider
Reported affiliate activity involving DragonForce ransomware deployment.
First seen: May 2025

Activity

Initial Access

CitrixBleed 2 exploitation
Huntress observed an intrusion cluster exploiting CVE-2025-5777 against Citrix NetScaler systems, with DragonForce ransomware deployed in the most advanced observed case.
Social engineering
DragonForce-associated affiliate activity has been publicly linked to social-engineering techniques targeting enterprise users and help desks.
Phishing, stolen credentials and exposed services
DragonForce-related intrusions have used phishing, exploitation of known vulnerabilities, leaked or stolen credentials, RDP and VPN weaknesses for initial access.
SimpleHelp RMM exploitation
Sophos MDR investigated an MSP compromise in which attackers used access through SimpleHelp to deploy DragonForce ransomware across multiple endpoints. Sophos assessed the vulnerability chain with medium confidence.
Social engineering by DragonForce-associated affiliates
Microsoft documented Octo Tempest activity using help-desk impersonation, password resets and other social-engineering techniques in attack chains that later deployed DragonForce.

Recent Observations

Continued victim publication
September 2026
Leak-site activity
New DragonForce victim claims continued to be published in September 2026.
CitrixBleed 2 intrusion chain
July 2026
Intrusion activity
Huntress documented a standardized intrusion chain involving CitrixBleed 2 exploitation, privilege escalation, remote-management tooling and DragonForce ransomware deployment.
CitrixBleed 2 deployment chain
July 2026
Intrusion activity
Huntress documented repeated Citrix NetScaler intrusion activity in which CVE-2025-5777 exploitation led through privilege escalation and remote-access tooling to DragonForce deployment.
Octo Tempest deploys DragonForce against ESXi
July 2025
Affiliate activity
Microsoft observed Octo Tempest deploying DragonForce ransomware with a particular focus on VMware ESX hypervisor environments.
SimpleHelp MSP compromise
June 2025
Intrusion activity
Sophos MDR investigated an MSP compromise involving SimpleHelp access, data exfiltration and DragonForce deployment across multiple endpoints.
DragonForce cartel model announced
March 2025
Operational change
DragonForce announced a distributed white-label model allowing affiliates to use its ransomware infrastructure and tooling while operating under independent branding.

TTPs

ATT&CK coverage: 11 techniques · 10 tactics
T1190 Exploit Public-Facing Application
VERIFIED
Initial Access
DragonForce-related intrusions have exploited public-facing Citrix NetScaler, Ivanti and other exposed infrastructure.
T1078 Valid Accounts
VERIFIED
Initial Access / Persistence
Leaked or stolen credentials and authenticated access have been used in DragonForce-related intrusion activity.
T1136.001 Create Account: Local Account
VERIFIED
Persistence
Operators created rogue local administrator accounts during observed DragonForce-related intrusion activity.
Show more TTPs (8)
T1219 Remote Access Software
VERIFIED
Command and Control
Remote-management tooling including ScreenConnect and Zoho Assist was observed in DragonForce deployment chains.
T1021.001 Remote Desktop Protocol
VERIFIED
Lateral Movement
RDP was used for interactive access after creation of administrator accounts.
T1569.002 Service Execution
VERIFIED
Execution
PsExec and related remote-execution techniques were observed during lateral movement.
T1003 OS Credential Dumping
VERIFIED
Credential Access
Mimikatz and credential-dumping activity have been documented in DragonForce-associated intrusions.
T1486 Data Encrypted for Impact
VERIFIED
Impact
DragonForce encrypts victim systems; Microsoft and CISA specifically documented deployments affecting VMware ESXi.
T1567.002 Exfiltration to Cloud Storage
VERIFIED
Exfiltration
DragonForce operators have used MEGA as one method for data exfiltration.
T1566 Phishing
VERIFIED
Initial Access
Phishing email is documented as an initial-access method in DragonForce-related intrusions.
T1133 External Remote Services
VERIFIED
Persistence / Initial Access
DragonForce operators have targeted RDP services and VPN weaknesses to obtain or maintain remote access.

Victims

Medical Department Store CLAIMED
September 11, 2026 3 tracker sources
rubbermill.com CLAIMED
September 6, 2026 3 tracker sources
Homewood Sales CLAIMED
September 6, 2026 3 tracker sources
Norwood Law Firm CLAIMED
September 6, 2026 3 tracker sources
Frato CLAIMED
August 24, 2026 3 tracker sources
Show more victims (5)
Criba CLAIMED
August 24, 2026 3 tracker sources
Brookview Financial CLAIMED
August 24, 2026 3 tracker sources
Wozair CLAIMED
August 24, 2026 3 tracker sources
Hogan Omidi P.C. CLAIMED
August 21, 2026 3 tracker sources
R & D Machine and Engineering CLAIMED
August 18, 2026 3 tracker sources

CVEs

Citrix — NetScaler ADC / NetScaler Gateway
Huntress observed exploitation in an intrusion cluster that culminated in DragonForce deployment.
Associated since: January 2026
Apache — Log4j
SentinelOne lists Log4Shell among vulnerabilities specifically associated with past DragonForce intrusions.
Associated since: May 2025
Ivanti — Connect Secure / Policy Secure
Authentication bypass associated with past DragonForce intrusions in SentinelOne reporting.
Associated since: May 2025
Show more CVEs (6)
Microsoft — Windows SmartScreen
Security-feature bypass associated with past DragonForce intrusions in SentinelOne reporting.
Associated since: May 2025
Ivanti — Connect Secure / Policy Secure
Command-injection vulnerability associated with past DragonForce intrusions.
Associated since: May 2025
Ivanti — Connect Secure / Policy Secure
Path-traversal vulnerability associated with past DragonForce intrusions.
Associated since: May 2025
SimpleHelp — SimpleHelp RMM
Sophos MDR assessed with medium confidence that attackers exploited this path-traversal vulnerability before deploying DragonForce.
Associated since: June 2025
SimpleHelp — SimpleHelp RMM
Sophos MDR assessed with medium confidence that this arbitrary file-upload vulnerability formed part of the pre-DragonForce SimpleHelp exploit chain.
Associated since: June 2025
SimpleHelp — SimpleHelp RMM
Sophos MDR assessed with medium confidence that this privilege escalation vulnerability formed part of the SimpleHelp chain.
Associated since: June 2025

Infrastructure

Leak / news site
Tor-based DragonForce leak and publication infrastructure
ONLINE
Last checked: September 15, 2026
Negotiation portal
Tor-based DragonForce negotiation infrastructure
Contact channel
Tox

Timeline

2026-09
Continued activity
DragonForce continued publishing new victim claims in September 2026.
2026-09
Continued leak-site activity
DragonForce continued publishing victim claims and operating Tor-based public infrastructure in September 2026.
2026-07
CitrixBleed 2 deployment chain
Huntress documented a repeated intrusion chain using CVE-2025-5777 that culminated in DragonForce ransomware deployment.
Show more events (6)
2025-07
Octo Tempest DragonForce deployment documented
Microsoft reported observed Octo Tempest deployment of DragonForce with particular focus on VMware ESX environments.
2025-06
SimpleHelp deployment chain documented
Sophos MDR investigated an MSP compromise involving SimpleHelp, data theft and DragonForce ransomware deployment.
2025-05
UK retail activity
DragonForce ransomware was publicly associated with high-profile cyberattacks affecting major UK retailers.
2025-05
Rival leak sites targeted
DragonForce was linked to defacement activity affecting BlackLock and Mamona leak sites during its cartel expansion.
2025-03
Cartel model announced
DragonForce announced a distributed white-label affiliate model on March 19, 2025.
2023-08
DragonForce emerges
DragonForce emerged as a ransomware-as-a-service operation.

Sources