logo

Inside the Dragon: DragonForce Ransomware Group

ID: 486816ce-3cd6-5983-b869-91308871fa3b

STIX ID: report--486816ce-3cd6-5983-b869-91308871fa3b

Feed Name: Group-IB Blog

Threat Score
78/100

Date Published: 2024-09-25

Date Updated: 2026-04-28

...
...

**Executive summary:** Group-IB provides a technical analysis of the DragonForce ransomware RaaS (active Aug 2023–Aug 2024) that leverages two ransomware builds (a LockBit 3.0 fork and a ContiV3-derived variant with BYOVD), an affiliate program offering 80% payouts, double-extortion tactics with a dedicated leak site, and operational tooling (SystemBC, Cobalt Strike, Mimikatz, network scanners); the report includes TTP mappings, a DFIR case study, IOCs (IPs and file hashes), and prioritized mitigations (MFA, EDR/XDR tuning, backups, patching, and incident response).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.