UK Cybercrime Journal: Sustained DragonForce Campaign
ID: 880f169b-c4a9-5144-9c47-3d52d4393b66
STIX ID: report--880f169b-c4a9-5144-9c47-3d52d4393b66
Feed Name: BushidoToken Blog
DragonForce RaaS affiliates posted multiple UK companies to their Tor data-leak site in May 2026, affecting organisations across professional services, finance, logistics, construction, technology, and retail; the group is opportunistic, exploits RDP/SSL‑VPN exposures and uses BYOVD to evade EDR, and has targeted backups and MSPs. The report highlights active exploitation evidence (recent victim postings and previous high-profile attacks), and advises patching VPNs, restricting RDP exposure, enforcing MFA and credential rotation, and maintaining offline backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
