CARDS
CARDS
DragonForce is retained as a financially motivated ransomware/extortion profile that has been reported as a RaaS and cartel-style operation. Public sources describe multiple boundaries that should not be collapsed automatically: DragonForce Malaysia hacktivist branding, DragonForce ransomware/RaaS operations, affiliate use of LockBit- and Conti-derived payloads, and Scattered Spider actors deploying DragonForce ransomware in some intrusions. IntelliOS treats those as source-backed relationships and deployment context, not proof that every named group or toolchain is the same actor. Current enrichment emphasizes DragonForce ransomware behavior, affiliate tooling, SimpleHelp exploitation reports, and public malware/file/network observables.
This profile is generated from the same canonical actor-card record used by the Threat Actor Cards directory, so aliases, targeting fields, activity notes, and source links stay aligned as the database is enriched.
Actor Card Detail
Identity
Aliases1
Source Boundary
SOCRadar is the retained baseline for this profile. IntelliOS preserves source labels as discovery and comparison signals until a cited source explicitly supports a merge, split, or actor-boundary change.
Targeting
Associated Activity1
ATT&CK IDs1
Campaign Context
| Campaign / Operation | Source-Backed Context |
|---|---|
| dragonforce Ransomware / Extortion Operations7 | dragonforce Ransomware / Extortion Operations is retained in the campaign database for dragonforce. DragonForce is a major ransomware-as-a-service operation first observed in August 2023 that launched a formal affiliate program offering 80% revenue share, then rebranded as a "ransomware cartel" in 2025, gaining notoriety for high-profile attacks on UK retailers Marks & Spencer, Co-op, and Harrods. |
Indicators
SOCRadar reports 2131 IOCs for this profile. IntelliOS currently retains 49 cited public observable/context rows; this is not the full possible public-source IOC corpus.
Source coverage: 5 source groups tracked; 4 currently contribute retained observable or context rows.
Retained Observables
Showing 49 of 49
| Type | Value | Source |
|---|---|---|
| SHA-256 Hash | 01f1e82d4c2b04a4652348fb18bb480396db2229c4fd22d2be1ea58e6bf4a5705 | Bitdefender |
| SHA-256 Hash | 1aed62a63b4802e599bbd33162319129501d603cceeb5e1eb22fd4733b3018a34 | Group-IB |
| SHA-256 Hash | 312ca1a8e35dcf5b80b1526948bd1081fed2293b31d061635e9f048f3fe5eb835 | Bitdefender |
| SHA-256 Hash | 5c54bd1aa2abf024f53490b7d93101496b5842a5a81a51955fe7f1d5e42814095 | Bitdefender |
| SHA-256 Hash | 7126b9932dc0cdfe751340edfa7c4a14b69262eb1afd0530e6d1fdb2e25986dd5 | Bitdefender |
| SHA-256 Hash | 88169b1d4778ed6c5fda97375efb5b9171ea52649c8715bb449801c39bce4ad45 | Bitdefender |
| SHA-256 Hash | 9165d4f3036919a96b86d24b64d75d692802c7513f2b3054b20be40c212240a54 | Group-IB |
| SHA-256 Hash | ba1be94550898eedb10eb73cb5383a2d1050e96ec4df8e0bf680d3e76a9e24295 | Bitdefender |
| SHA-256 Hash | bfc2ef3b404294fe2fa05a8b71c7f786b58519175b7202a69fe30f45e607ff1c4 | Group-IB |
| SHA-256 Hash | cee6a7663fad90c807c9f5ea8f689afd0e4ece04f8c55d7a047a7215db6be2106 | RH-ISAC |
| SHA-256 Hash | d4de7d7990114c51056afeedb827d880549d5761aac6bdef0f14cb17c25103b35 | Bitdefender |
| SHA-256 Hash | e1b147aa2efa6849743f570a3aca8390faf4b90aed490a5682816dd9ef10e4735 | Bitdefender |
| MD5 Hash | 97B70E89B5313612A9E7A339EE82AB674 | Group-IB |
| MD5 Hash | A50637F5F7A3E462135C0AE7C7AF0D914 | Group-IB |
| MD5 Hash | BB7C575E798FF5243B5014777253635D4 | Group-IB |
| MD5 Hash | C111476F7B394776B515249ECB6B20E64 | Group-IB |
| Filename | a65.exe4 | Group-IB |
| Filename | df.exe4 | Group-IB |
| Filename | netscanold.exe4 | Group-IB |
| Filename | PUSH PUSh PUUUUUSH.bat6 | RH-ISAC |
| Filename | socks.exe4 | Group-IB |
| File Extension | .dragonforce_encrypted4 | Group-IB |
| File Path | C:\ProgramData\JWrapper-Remote Access\JWApps\SharedConfig\working\toolbox-9759076704687761247\win.exe6 | RH-ISAC |
| File Path | C:\Users\<user>\Videos\PUSH PUSh PUUUUUSH.bat6 | RH-ISAC |
| Command Line | cmd.exe /c C:\Windows\System32\wbem\WMIC.exe shadowcopy where "ID='%s'" delete4 | Group-IB |
| Command Line | SELECT * FROM Win32_ShadowCopy4 | Group-IB |
| Tool / Process | ADFind4 | Group-IB |
| Tool / Process | BYOVD4 | Group-IB |
| Tool / Process | Cobalt Strike4 | Group-IB |
| Tool / Process | ContiV3 fork4 | Group-IB |
| Tool / Process | LockBit 3.0 fork4 | Group-IB |
| Tool / Process | Mimikatz4 | Group-IB |
| Tool / Process | RDP4 | Group-IB |
| Tool / Process | RentDrv.sys4 | Group-IB |
| Tool / Process | SoftPerfect Network Scanner4 | Group-IB |
| Tool / Process | SystemBC4 | Group-IB |
| Tool / Process | TrueSight.sys4 | Group-IB |
| CVE | CVE-2024-577266 | RH-ISAC |
| CVE | CVE-2024-577276 | RH-ISAC |
| CVE | CVE-2024-577286 | RH-ISAC |
| Network Indicator | http://185.73.125.8/broadcast4 | Group-IB |
| Network Indicator | 185.73.125.84 | Group-IB |
| Network Indicator | 94.232.46.2024 | Group-IB |
| Mutex | dragonforce_encrypted_system4 | Group-IB |
| Campaign Context | Bitdefender described DragonForce as shifting from a traditional RaaS operation toward a cartel-style model and noted debate around boundaries with the earlier DragonForce Malaysia hacktivist label.5 | Bitdefender |
| Campaign Context | CISA's Scattered Spider advisory notes Scattered Spider threat actors have used DragonForce ransomware; IntelliOS keeps this as a deployment relationship, not an automatic merge between DragonForce and Scattered Spider.3 | CISA AA23-320A |
| Campaign Context | Group-IB linked DragonForce intrusion activity to SystemBC, Cobalt Strike, Mimikatz, SoftPerfect Network Scanner, ADFind, RDP, and event-log clearing; IntelliOS retains these as intrusion-context observables, not proof that every related tool use is DragonForce.4 | Group-IB |
| Campaign Context | Group-IB reported DragonForce affiliate-panel support for two Windows ransomware variants: a LockBit fork and a customized ContiV3-based build with BYOVD, scheduled-task persistence, and expanded encryption customization.4 | Group-IB |
| Campaign Context | RH-ISAC summarized Sophos reporting that attackers exploited SimpleHelp CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728 to deploy DragonForce ransomware through MSP infrastructure.6 | RH-ISAC |
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar2 | 2131 | 0 | Reported IOC count retained; underlying SOCRadar feed values are not republished unless stored as cited public observables. |
| CISA/FBI/International Partners3 | N/A | 1 | Public observables or source-context rows retained and displayed. |
| Group-IB4 | N/A | 31 | Public observables or source-context rows retained and displayed. |
| Bitdefender5 | N/A | 9 | Public observables or source-context rows retained and displayed. |
| RH-ISAC6 | N/A | 8 | Public observables or source-context rows retained and displayed. |
IntelliOS Intel Products
None Found
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | DragonForce | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | DragonForce | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor/ransomware | Baseline actor-card corpus source for retained profile fields. |
| 2 | SOCRadar Actor Profile https://socradar.io/free-tools/ransomware-intelligence/groups/dragonforce | Per-actor SOCRadar profile source for ransomware profile metadata and IOC count when available. |
| 3 | CISA AA23-320A: Scattered Spider notes DragonForce ransomware deployment https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a | Threat Actor Context |
| 4 | Group-IB: Inside the Dragon: DragonForce Ransomware Group https://www.group-ib.com/blog/dragonforce-ransomware/ | Threat Research |
| 5 | Bitdefender: DragonForce: The Ransomware Cartel Guarding Its Burrow https://businessinsights.bitdefender.com/dragonforce-ransomware-cartel | Threat Research |
| 6 | RH-ISAC: DragonForce Actors Target SimpleHelp Vulnerabilities https://rhisac.org/threat-intelligence/dragonforce-actors-target-simplehelp-vulnerabilities-to-attack-msp-customers/ | Sector ISAC Advisory |
| 7 | dragonforce - Ransomware.live group profile https://www.ransomware.live/group/dragonforce | Ransomware.live campaign row source for dragonforce Ransomware / Extortion Operations. |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for DragonForce.
No possible same-actor, alias reuse, sub-cluster, duplicate-boundary, or external-source collision is currently retained for this actor.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| None retained | No candidate records | No shared evidence recorded | No collision action needed. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |