logo

The DragonForce Cartel: Scattered Spider at the gate

ID: 1f79496a-cd38-50ae-b868-d11608cd7bc5

STIX ID: report--1f79496a-cd38-50ae-b868-d11608cd7bc5

Feed Name: TRU Security by Acronis

Threat Score
85/100

Date Published: 2025-11-04

Date Updated: 2026-07-24

...
...

**Executive summary:** Acronis TRU analyzed DragonForce, a Conti-derived ransomware cartel active since 2023, describing its Conti/LockBit lineage, affiliate model (white-label encryptors, Devman/Mamona links), technical changes (MinGW build, ChaCha20+RSA encryption, encrypted configuration), abuse of vulnerable drivers (truesight.sys, rentdrv2.sys) to terminate security processes, collaboration with Scattered Spider for initial access, and an active leak site with 200+ exposed victims across multiple sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.