The Godfather of Ransomware? Inside Cartel Ambitions
Essential information
- Published
- 04/02/2026 11:13
- Modified
- 04/02/2026 21:20
- Tags
- 2026-02-04 cartel cross-platform cybercrime data-audit dragonforce dual-extortion encryption raas ransomware
- Related entities
- 7 observables, 1 intrusion sets (apt), 17 techniques (mitre), 1 malware, 6 others
Description
DragonForce, a ransomware group that emerged in late 2023, has become a significant cyber threat. They employ a dual-extortion strategy, encrypting and exfiltrating data, and have targeted various sectors, particularly manufacturing and construction. The group offers a flexible ransomware-as-a-service platform with advanced features, supporting multiple platforms and encryption modes. DragonForce has announced a shift to a cartel model, allowing affiliates to create their own brands. They've also introduced automated registration for new affiliates and a 'Company Data Audit' service to enhance extortion campaigns. The group has engaged in conflicts with rival ransomware operations and claims to have formed a coalition with other major groups. While their connection to DragonForce Malaysia remains unsubstantiated, technical analysis reveals similarities with other ransomware families and sophisticated attack techniques.