Threadlinqs IntelligenceStart free

Threat actorMYTracked since 2026-02

DragonForce

Also known as:DragonForce RansomwareDragonForce CartelScattered Spider

As of 2026-10-01, DragonForce is a MY-nexus threat actor tracked by Threadlinqs Intelligence across 8 threats spanning malware, ransomware, ics scada. Also known as DragonForce Ransomware, DragonForce Cartel, Scattered Spider. ATT&CK coverage spans 99 techniques across 16 tactics in 8 of 8 tracked threats. Most-observed techniques: T1685 (Disable or Modify Tools), T1190 (Exploit Public-Facing Application), T1046 (Network Service Discovery).

Tracked threats
82 critical · 6 high
First seen
2026-02-12
Last seen
2026-10-01
ATT&CK techniques
99across 8 of 8 threats
Related CVEs
25Referenced by its activity
Attribution
MYNation or origin
Nation: MY · 8 tracked threat(s) · Categories: MALWARE, RANSOMWARE, ICS_SCADA

Activity timeline

DragonForce appears in 8 tracked threats between and ; the busiest month was 2026-09 with 3 reports.

ATT&CK techniques observed

99 techniques observed across 8 of 8 tracked threats · Stealth (formerly Defense Evasion) (14), Command and Control (11), Discovery (10), Impact (8), Persistence (8), Credential Access (7)
  • T1685 Disable or Modify Tools — Defense Impairmentobserved in 8 of 8 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 7 of 8 tracked threats
  • T1046 Network Service Discovery — Discoveryobserved in 5 of 8 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 5 of 8 tracked threats
  • T1490 Inhibit System Recovery — Impactobserved in 5 of 8 tracked threats
  • T1003 OS Credential Dumping — Credential Accessobserved in 4 of 8 tracked threats
  • T1021 Remote Services — Lateral Movementobserved in 4 of 8 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 8 tracked threats
  • T1133 External Remote Services — Initial Accessobserved in 4 of 8 tracked threats
  • T1567 Exfiltration Over Web Service — Exfiltrationobserved in 4 of 8 tracked threats
  • T1055 Process Injection — Stealth (formerly Defense Evasion)observed in 3 of 8 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 3 of 8 tracked threats
  • T1087.002 Account Discovery: Domain Account — Discoveryobserved in 3 of 8 tracked threats
  • T1090.002 External Proxy — Command and Controlobserved in 3 of 8 tracked threats
  • T1199 Trusted Relationship — Initial Accessobserved in 3 of 8 tracked threats

Tracked threats

Related CVEs

25 CVEs referenced by tracked DragonForce activity