DragonForce Ransomware Group Expands Its Influence with Cartel-like Operations and Targeting 363 Companies Since 2023
ID: c2e23e7e-b071-5f7c-9979-10fd6cd9bef7
STIX ID: report--c2e23e7e-b071-5f7c-9979-10fd6cd9bef7
Feed Name: cybersecurityNews.com
Threat Score
DragonForce is a Ransomware-as-a-Service cartel active since December 2023 that has publicly targeted hundreds of companies (363 identified victims) and expanded its operational and technical capabilities—leveraging dark-web recruitment, bespoke affiliate tools (e.g., RansomBay), harassment services, and enhanced ransomware builders that use BYOVD, ChaCha8-encrypted configurations, and new per-extension encryption rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
