Ransomware Group intelligence
Dragonforce
ActiveTrack Dragonforce with 717 published victims and 4 known leak locations in a single intelligence view.
Overview
Dragonforce is tracked by Breach House as a ransomware group with 717 published victims.
United States is currently the most targeted country in this dataset.
4 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (4)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Up checked 1h ago | 3pktcrcbmssvrnwe5skburdwe2h3v6ibdnn5kbjqihsg6eu6s6b7ryqd.onion |
| Leak location 1 | Onion service | Up checked 1h ago | z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion |
| Leak location 4 | Onion service | Down checked 1h ago | dragongoztkdfmnd7jkchznd3fvkpdmeh4vhbt6p3usrlsoy5dw2bhyd.onion |
| Leak location 3 | Onion service | Down checked 1h ago | dragonforxxbp3awc7mzs5dkswrua3znqyx5roefmi4smjrsdi22xwqd.onion |
Top Activity Sectors (17)
- Communication / Marketing 130
- Manufacturing / Engineering 88
- Finance / Legal / Insurance 70
- Services 56
- IT 46
- Construction / Real Estate 45
- Healthcare / Pharma 34
- Hospitality / Food & Beverage / Tourism 25
- Not identified 24
- Energy 22
- Retail / E-commerce 21
- Transportation / Travel / Logistics 20
- Public Sector 20
- Education 14
- Agriculture / Food 13
- NGOs / Associations 12
- Telecommunications 10
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Dragonforce, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: dragonforce executes malicious payloads via PowerShell scripts injected into legitimate processes for command execution.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: dragonforce disables antivirus tools by terminating security processes and modifying Windows Defender settings.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.002 Software Packing Stealth
What they do: dragonforce packs its malware binaries to evade static detection by security tools.
What that means: Adversaries may perform software packing or virtual machine software protection to conceal their code.
-
T1070.004 File Deletion Stealth
What they do: dragonforce deletes Volume Shadow Copies via vssadmin /delete shadows to prevent rollback recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1110 Brute Force Credential Access
What they do: dragonforce brute-forces local accounts using Hydra to obtain credentials for initial access.
What that means: Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
-
T1018 Remote System Discovery Discovery
What they do: dragonforce discovers remote hosts via SMB enumeration to identify high-value targets across networks.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: dragonforce scans network shares using net use commands to discover victim file structures for targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: dragonforce moves laterally through SMB shares using mapped drives to access additional systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: dragonforce encrypts victim files using a custom ransomware binary with AES-256 encryption keys.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: dragonforce runs system shutdown commands to prevent recovery attempts and maximize disruption.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (14)
▼Software Dragonforce has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Offensive security tooling
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
readme.xt
Good afternoon, As you can see you have been attacked by a ransomware program! We The DragonForce Ransomware Cartel offer you to make a deal with us. We can make a deal with you, all you need to do is contact us by following the instructions below. We are in no way connected to politics, we always keep our word. You have a chance to decrypt your files and avoid being published on our blog! Use this opportunity and also don't waste your time. The approximate date of deletion of the decryptor program, as well as publication on our blog 26/04/2025 00:00 UTC. - # 1 Communication Process, In order to contact us you need to click on the special link below, which is listed in #2. After that the negotiation process begins, in which you have the opportunity to request several things from us, 1. make a test decrypt. 2. get a list of the files stolen from you. At the conclusion of our negotiations we agree on a price, we set the price ourselves based on your income/your insurance. We scrutinize your documents and are well aware of how much income your company has per year. - # 2 Access to the meeting room, To access us please download Tor Browser which is available here. (https://www.torproject.org/) Once you download the special anonymous browser you need to follow this link, http://3pktcrcbmssvrnwe5skburdwe2h3v6ibdnn5kbjqihsg6eu6s6b7ryqd.onion Your unique ID: [snap] - use it to enter our meeting room. - # 3 Additional Support Contacts, Tox: 1C054B722BCBF41A918EF3C485712742088F5C3E81B2FDD91ADEA6BA55F4A856D90A65E99D20 - # 4 Recommendations, Do not try to recover your files with third-party programs, you will only do harm. Do not turn off / reboot your computer. Be courteous in our meeting room. Do not procrastinate. - # 5 Blog and News, Blog: http://z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion DragonNews: http://z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion/news
[rand].README.txt
Hello! Your files (orcl, IADeAPP, [snip] dbs) have been stolen from your network and encrypted with a strong algorithm. We work for money and are not associated with politics. All you need to do is contact us and pay. --- Our communication process: 1. You contact us. 2. We send you a list of files that were stolen. 3. We decrypt 1 file to confirm that our decryptor works. 4. We agree on the amount, which must be paid using BTC. 5. We delete your files, we give you a decryptor. 6. We give you a detailed report on how we compromised your company, and recommendations on how to avoid such situations in the future. --- Client area (use this site to contact us): Link for Tor Browser: http://3pktcrcbmssvrnwe5skburdwe2h3v6ibdnn5kbjqihsg6eu6s6b7ryqd.onion >>> Use this ID: [snip] to begin the recovery process. * In order to access the site, you will need Tor Browser, you can download it from this link: https://www.torproject.org/ --- Additional contacts: Support Tox: 1C054B722BCBF41A918EF3C485712742088F5C3E81B2FDD91ADEA6BA55F4A856D90A65E99D20 --- Recommendations: DO NOT RESET OR SHUTDOWN - files may be damaged. DO NOT RENAME OR MOVE the encrypted and readme files. DO NOT DELETE readme files. --- Important: If you refuse to pay or do not get in touch with us, we start publishing your files. 21/01/2024 00:00 UTC the decryptor will be destroyed and the files will be published on our blog. Blog: http://z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion Sincerely, 01000100 01110010 01100001 01100111 01101111 01101110 01000110 01101111 01110010 01100011 01100101
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (717)
Search, filter and paginate the victim timeline for Dragonforce. Showing 701–717 of 717.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Heart of Texas Region MHMR id10020 View details | Services | — | ||
|
Heart of Texas Region MHMR Center strives to deliver accessible and responsive support services to individuals and families coping with mental illness, intellec... |
|||||
| Ransomware | PCTEL id10019 View details | Telecommunications | — | ||
|
PCTEL, Inc., together with its subsidiaries, delivers performance critical telecom solutions in the Asia Pacific, Europe, the Middle East, Africa, and the Ameri... |
|||||
| Ransomware | Agl Welding Supply id10018 View details | Other | — | ||
|
Family owned and operated since 1920, AGL holds itself to a higher standard. For us, that means living our corporate values and giving back to the communities w... |
|||||
| Ransomware | Grayhill id10017 View details | Manufacturing / Engineering | — | ||
|
Founded in 1943, Grayhill is a company that manufactures electronic components including, optical and mechanical encoders, rotary switches, and joysticks. Grayh... |
|||||
| Ransomware | Leedarson Lighting id10016 View details | Services | — | ||
|
As a worldwide ODM, LEEDARSON partners with businesses to help them design, manufacture, test, certify, kit and deliver extraordinary IoT devices. They apply th... |
|||||
| Ransomware | Coca-Cola Singapore id10015 View details | Singapore | Hospitality / Food & Beverage / Tourism | — | |
|
Coca-Cola Singapore produces and distributes carbonated beverages. The Company offers soft drink, juice, tea, and water. |
|||||
| Ransomware | Shorts id10014 View details | Services | — | ||
|
Shorts is a long standing local business which has grown rapidly in recent years. We are a firm where capable, ambitious and knowledgeable individuals can make ... |
|||||
| Ransomware | World Emblem International id10013 View details | Manufacturing / Engineering | — | ||
|
Founded in 1993, World Emblem International is an apparel company that specializes in the manufacturing and design of emblems. They are based in Miami, Florida. |
|||||
| Ransomware | The GBUAHN id10012 View details | Healthcare / Pharma | — | ||
|
GBUAHN is the first health organization in WNY to utilize Tyto Care's cutting-edge solution for remote chronic care management The Greater Buffalo United Accoun... |
|||||
| Ransomware | Baden id10011 View details | Switzerland | Education | — | |
|
All levels of education through to the end of secondary school (higher education entrance qualification) can be completed in Baden. The city also boasts ultra-m... |
|||||
| Ransomware | Dafiti Argentina id10010 View details | Argentina | Communication / Marketing | — | |
|
Comprar zapatos, ropa y accesorios por internet en Dafiti Argentina, accedé a lo mejor de la moda. Envío gratis desde $3799 según tu zona, cambio y devolución g... |
|||||
| Ransomware | Lunacon Construction Group id10009 View details | Construction / Real Estate | — | ||
|
Lunacon Construction Group was founded in Miami, FL in 2007, based on the principles of integrity, diversity, and excellence in building. Over the past decade, ... |
|||||
| Ransomware | Tglt id10008 View details | Construction / Real Estate | — | ||
|
TGLT S.A. operates as a residential real estate development company. The company develops and constructs multi-family residences and mixed-use projects in Bueno... |
|||||
| Ransomware | Seven Seas id10007 View details | Manufacturing / Engineering | — | ||
|
Established in 1971, Seven Seas is a global maritime services group specializing in the provision of general ship supplies, stores, spare parts, and leading tec... |
|||||
| Ransomware | Decina id10006 View details | Australia | Manufacturing / Engineering | — | |
|
Decina has made over one million baths in our Queensland factory since 1989 and is 100% Australian owned. Decina is Australia's first choice in bathroom product... |
|||||
| Ransomware | Cooper Research Technology id10005 View details | United Kingdom | IT | — | |
|
Cooper Research Technology Limited (also known as Cooper Technology) is a British manufacturer of high-performance civil engineering materials testing equipment... |
|||||
| Ransomware | Greater Cincinnati Behavioral Health id10004 View details | Healthcare / Pharma | — | ||
|
Greater Cincinnati Behavioral Health Services (GCB) is the most comprehensive mental health provider in Southwestern Ohio and Northern Kentucky serving people w... |
|||||