DragonForce Ransomware Gang | From Hacktivists to High Street Extortionists
Essential information
- Published
- 03/05/2025 15:28
- Modified
- 05/05/2025 19:39
- Tags
- 2025-05-03 CVE-2021-44228 CVE-2023-46805 CVE-2024-21412 CVE-2024-21887 CVE-2024-21893 cobalt strike dragonforce ransomware extortion multi-extortion ransomware systembc white-label
- Related entities
- 1 intrusion sets (apt), 11 techniques (mitre), 7 others
Description
The DragonForce ransomware group, initially a pro-Palestine hacktivist operation, has evolved into a profit-driven extortion enterprise targeting UK retailers and various global entities. Emerging in August 2023, the group now employs a multi-extortion model, threatening data leaks and reputational damage. Their tactics include phishing, vulnerability exploitation, and credential stuffing for initial access. DragonForce has developed its own ransomware based on leaked LockBit and Conti code, offering customizable payloads for different platforms. Recently, they introduced a 'white-label' service allowing affiliates to disguise attacks under different brands. The group's expansion and self-branding as a 'Ransomware Cartel' indicate a strategic move to elevate their status in the cybercrime landscape.