Netskope Threat Labs

DragonForce

ATP Sandbox Adv. HeuristicsAV

DragonForce is a ransomware operation that runs an affiliate program, rents out its encryptor and infrastructure, and pressures victims through a leak site. Its tooling supports Windows, Linux, and VMware ESXi systems, and researchers have observed high profile intrusions in which well known social engineering crews used the brand. The operation's growth reflects the modern pattern of brands and affiliate teams reshuffling while the underlying tactics stay constant.

First seen
May 2025
Last seen
October 2026
Dragonforce
Alert Name
Gen:Variant.Ransom.DragonForce.6
Win32.Ransomware.Dragonforce
Win32.Ransomware.DragonForce