The DragonForce Cartel: Scattered Spider at the gate
ID: 1f79496a-cd38-50ae-b868-d11608cd7bc5
STIX ID: report--1f79496a-cd38-50ae-b868-d11608cd7bc5
Feed Name: TRU Security by Acronis
**Executive summary:** Acronis TRU analyzed DragonForce, a Conti-derived ransomware cartel active since 2023, describing its Conti/LockBit lineage, affiliate model (white-label encryptors, Devman/Mamona links), technical changes (MinGW build, ChaCha20+RSA encryption, encrypted configuration), abuse of vulnerable drivers (truesight.sys, rentdrv2.sys) to terminate security processes, collaboration with Scattered Spider for initial access, and an active leak site with 200+ exposed victims across multiple sectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
