216.73.217.22

The Godfather of Ransomware? Inside Cartel Ambitions

· Published 04/02/2026 11:13 · Modified 04/02/2026 21:20

Export JSON

Essential information

Published
04/02/2026 11:13
Modified
04/02/2026 21:20
Tags
2026-02-04 cartel cross-platform cybercrime data-audit dragonforce dual-extortion encryption raas ransomware
Related entities
7 observables, 1 intrusion sets (apt), 17 techniques (mitre), 1 malware, 6 others

Description

, a group that emerged in late 2023, has become a significant cyber threat. They employ a strategy, encrypting and exfiltrating data, and have targeted various sectors, particularly manufacturing and construction. The group offers a flexible -as-a-service platform with advanced features, supporting multiple platforms and modes. has announced a shift to a model, allowing affiliates to create their own brands. They've also introduced automated registration for new affiliates and a 'Company Data Audit' service to enhance extortion campaigns. The group has engaged in conflicts with rival operations and claims to have formed a coalition with other major groups. While their connection to Malaysia remains unsubstantiated, technical analysis reveals similarities with other families and sophisticated attack techniques.

External references