logo

DragonForce: The Rise of a New “Ransomware Cartel” Built on LockBit and Conti DNA

ID: 0de55606-a6d6-5f9e-aa25-03ca6be920f0

STIX ID: report--0de55606-a6d6-5f9e-aa25-03ca6be920f0

Feed Name: securityonline.info

Threat Score
76/100

Date Published: 2026-01-19

Date Updated: 2026-04-23

Author: Ddos

...
...

S2W's analysis profiles DragonForce as a rapidly expanding, cartel-style ransomware operation called 'Ransombay' that customizes payloads for affiliates, recruits pentesters and initial access brokers, and has absorbed rival groups (e.g., BlackLock) via infrastructure compromise; the malware reuses LockBit/Conti code, employs ChaCha8 and RSA-4096, obfuscates strings, marks encrypted files with a .RNP extension, and researchers recovered a decryptor tied to a hardcoded RSA private key, indicating operational errors that may allow victim recovery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.