DragonForce
Essential information
- Confidence
- 100/100
- Published
- 20/12/2025 08:53
- Modified
- 16/06/2026 19:48
- Updated at
- 16/06/2026 19:48
- Revoked
- No
- Author / Source
- Ransomware.Live
- Resource level
- —
- Primary motivation
- —
- Related entities
- 6 reports, 61 attack patterns (mitre), 8 malware, 9 sectors, 18 countries, 84 indicators, 8 vulnerabilities (cve), 29 organization
Description
Marking (TLP)
TLP:CLEAR
Labels
ransomware
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (6)
-
AlienVault Confidence 100 3 CVEs 18 MITREs 2 Malwares 26 IOCs 26 Observables 1 APT
-
17 MITREs 1 Malware 7 Observables 1 APT
-
15 MITREs 5 Malwares 1 APT
-
11 MITREs 1 APT
-
5 CVEs 10 MITREs 1 Malware 17 Observables 1 APT
-
5 MITREs 2 Malwares 5 Observables 1 APT
Attack patterns (MITRE) (61)
-
T1078.003 usesLocal Accounts MITRE
-
T1566.001 usesSpearphishing Attachment MITRE
-
T1560 usesArchive Collected Data MITRE
-
T1566.003 usesSpearphishing via Service MITRE
-
T1547.001 usesRegistry Run Keys / Startup Folder MITRE
-
Credential Stuffing usesCredential Stuffing MITRE
-
T1059 usesCommand and Scripting Interpreter MITRE
-
T1573 usesEncrypted Channel MITRE
-
T1566.002 usesSpearphishing Link MITRE
-
T1055 usesProcess Injection MITRE
-
T1136 usesCreate Account MITRE
-
T1133 usesExternal Remote Services MITRE
Malware (8)
-
LockBit usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Global usesFamily
-
Conti usesFamily
-
DragonForce usesFamily
-
Mamona usesFamily
-
Backdoor.Turn usesFamily
-
Devman usesFamily
-
Conti - S0575 usesFamily
Sectors (9)
-
Technology targets
-
Manufacturing targets
-
Finance targets
-
Retail targets
-
Healthcare targets
-
Construction targets
-
Insurance services targets
-
Transportation targets
-
Agriculture Food Production targets
Countries (18)
-
United States of America targets
-
Finland targets
-
Israel targets
-
Germany targets
-
Slovakia targets
-
Mexico targets
-
Canada targets
-
Switzerland targets
-
Taiwan targets
-
Guatemala targets
-
India targets
-
Italy targets
Indicators (84)
-
stix 100/100· Valid until 01/11/2026 · Source: AlienVault
-
stix 100/100· Valid until 12/06/2027 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 29/04/2026 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 29/04/2026 · Source: AlienVault
-
stix 100/100· Valid until 01/11/2026 · Source: AlienVault
-
stix 100/100· Valid until 12/06/2027 · Source: AlienVault
-
professionalhomebasedbusiness.comindicatesstix 100/100· Valid until 11/11/2026 · Source: AlienVault -
stix 100/100 Revoked· Valid until 24/02/2026 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 25/07/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 24/02/2026 · Source: AlienVault
-
stix 100/100 Revoked
CoinMiner
· Valid until 02/12/2025 · Source: AlienVault -
stix 100/100 Revoked· Valid until 04/12/2025 · Source: AlienVault
Vulnerabilities (CVE) (8)
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web …
- Attack vector
- Network
- Published
- 10/01/2024
- Modified
- 27/05/2026
Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass.
- Attack vector
- Network
- Published
- 13/02/2024
- Modified
- 27/05/2026
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the …
- Attack vector
- Network
- Published
- 10/01/2024
- Modified
- 27/05/2026
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) …
- Attack vector
- Network
- Published
- 31/01/2024
- Modified
- 27/05/2026
Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
- Attack vector
- Network
- Published
- 10/12/2021
- Modified
- 27/05/2026
The GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in one of its IOCTL handlers. A user-mode process …
- Attack vector
- LOCAL
- Published
- 28/10/2025
- Modified
- 30/01/2026
The wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process Light) process via an IOCTL (which …
- Attack vector
- LOCAL
- Published
- 08/01/2024
- Modified
- 16/06/2026
A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege user to send crafted IOCTL …
- Attack vector
- LOCAL
- Published
- 11/06/2025
- Modified
- 16/06/2026
Organization (29)
-
Caramel targets
-
Dynex/Rivett targets
-
Váhostav targets
-
SINBON Electronics Co., Ltd targets
-
Colonial Metals targets
-
Barnes & Jones targets
-
National Credit Regulator (NCR) targets
-
tazzetti.com targets
-
[Redacted] Takedown Notice #2054 targets
-
Advanced Rehabilitation Technology targets
-
Tri-State Metal Roofing Supply targets
-
Burnex targets