Dragon RaaS | Pro-Russian Hacktivist Group Aims to Build on "The Five Families" Cybercrime Reputation
Essential information
- Published
- 19/03/2025 20:40
- Modified
- 20/03/2025 09:43
- Tags
- 2025-03-19 CVE-2022-0073 CVE-2022-0074 CVE-2023-2359 CVE-2023-47784 CVE-2023-6925 CVE-2024-3806 CVE-2024-3807 CVE-2024-3808 CVE-2024-3809 CVE-2024-47374 cybercrime defacement dragon raas hacktivism pro-russian ransomware stormcry vulnerability exploitation webshell
- Related entities
- 1 intrusion sets (apt), 13 techniques (mitre), 2 malware, 13 others
Description
Dragon RaaS is a ransomware group that emerged in July 2024 as an offshoot of Stormous, part of a larger cybercrime syndicate known as 'The Five Families'. The group markets itself as a sophisticated Ransomware-as-a-Service operation but often conducts defacements and opportunistic attacks rather than large-scale ransomware extortion. Dragon RaaS primarily targets organizations in the US, Israel, UK, France, and Germany, exploiting vulnerabilities in web applications, using brute-force attacks, and leveraging stolen credentials. The group operates two ransomware strains: a Windows-focused encryptor based on StormCry and a PHP webshell. Despite claims of creating a unique ransomware variant, analysis reveals that Dragon RaaS's payloads are slightly modified versions of StormCry.