White Paper
THREAT PROFILE: DragonForce Ransomware
DragonForce is a ransomware-as-a-service (RaaS) group first identified in 2023 that has evolved into a more sophisticated operation, reportedly adopting a white-label cartel model by 2025. The group uses a double-extortion strategy, encrypting systems while stealing sensitive data and threatening to publish it on a data leak site if victims do not pay. This threat profile examines DragonForce’s operations, targeted industries and regions, exploited vulnerabilities, known tools, and associations with other threat actors. The report also analyzes attack behaviors across both Windows and Linux environments, details the ransomware kill chain, and maps tactics and techniques to the MITRE ATT&CK framework. By understanding how DragonForce gains access, escalates privileges, moves laterally, exfi
