DragonForce Ransomware Group Targets Saudi Arabia with Large-Scale Data Breach
ID: d943a29e-8417-5b64-8d1e-c06996b1705b
STIX ID: report--d943a29e-8417-5b64-8d1e-c06996b1705b
Feed Name: securityonline.info
DragonForce, a Ransomware-as-a-Service group, conducted a major cyberattack against a large Saudi Arabian enterprise in the real estate/construction sector, exfiltrating over 6 TB of sensitive data and subsequently publishing it after an extortion deadline. The report describes the group's affiliate-driven RaaS operations, advanced TTPs (including phishing, RDP/VPN exploitation, automated data exfiltration via WebDAV, and DLS anti-indexing measures), and identifies several exploited CVEs, highlighting elevated risk to high-value organizations in the region.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
