DragonForce Ransomware Operators Hint at Ties to Russian Federation
ID: 1c47d403-f5bd-5727-9dc2-7497dafce7c5
STIX ID: report--1c47d403-f5bd-5727-9dc2-7497dafce7c5
Feed Name: Halcyon Blog
A reported ransomware attack by the group DragonForce forced a major UK retailer to suspend its click-and-collect service and is linked to other victims including Co-op (where member data was stolen). The group operates a white-label ransomware-as-a-service model, claims responsibility for 167 victims across 32 countries, and publicly warned affiliates not to target Russia or former Soviet states—an indication the gang may be serving Russian geopolitical interests as a proxy while continuing criminal extortion operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
