logo

Deep dive into DragonForce ransomware and its Scattered Spider connection

ID: 5f8858fb-e859-5c35-89f5-2323ab080cbd

STIX ID: report--5f8858fb-e859-5c35-89f5-2323ab080cbd

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-12-03

Date Updated: 2026-07-18

Author: Sponsored by Acronis

...
...

Security researchers analyzed DragonForce, a ransomware-as-a-service operation that rebranded as a "ransomware cartel," detailing its partnership with Scattered Spider for initial access and its use of vulnerable drivers (truesight.sys, rentdrv2.sys), RMM tools, MFA bypass techniques, and multi-platform encryption (Windows, Linux, ESXi) to conduct large-scale extortion and publish victim data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.