216.73.217.22

The DragonForce Cartel: Scattered Spider at the gate

· Published 05/11/2025 09:36 · Modified 07/11/2025 10:20

Export JSON

Essential information

Published
05/11/2025 09:36
Modified
07/11/2025 10:20
Tags
2025-11-05 affiliate program byovd cartel conti devman dragonforce encryption global mamona ransomware scattered spider social engineering
Related entities
1 intrusion sets (apt), 15 techniques (mitre), 5 malware, 4 others

Description

, a -as-a-service group active since 2023, has rebranded as a and formed alliances with groups like , LAPSUS$, and ShinyHunters. The group uses -derived code and employs attacks to terminate processes. has expanded its , allowing partners to white-label payloads and create variants. The group has exposed over 200 victims on its leak site, targeting various sectors. 's partnership with , known for sophisticated techniques, has led to high-profile breaches. The group's samples show significant overlap with 's leaked source files and use ChaCha20 .

External references