Activity timeline
DragonForce appears in 8 tracked threats between and ; the busiest month was 2026-09 with 3 reports.
ATT&CK techniques observed
- T1685 Disable or Modify Tools — Defense Impairmentobserved in 8 of 8 tracked threats
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 7 of 8 tracked threats
- T1046 Network Service Discovery — Discoveryobserved in 5 of 8 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 5 of 8 tracked threats
- T1490 Inhibit System Recovery — Impactobserved in 5 of 8 tracked threats
- T1003 OS Credential Dumping — Credential Accessobserved in 4 of 8 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 4 of 8 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 8 tracked threats
- T1133 External Remote Services — Initial Accessobserved in 4 of 8 tracked threats
- T1567 Exfiltration Over Web Service — Exfiltrationobserved in 4 of 8 tracked threats
- T1055 Process Injection — Stealth (formerly Defense Evasion)observed in 3 of 8 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 3 of 8 tracked threats
- T1087.002 Account Discovery: Domain Account — Discoveryobserved in 3 of 8 tracked threats
- T1090.002 External Proxy — Command and Controlobserved in 3 of 8 tracked threats
- T1199 Trusted Relationship — Initial Accessobserved in 3 of 8 tracked threats
Tracked threats
- DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2HIGH
- Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate DevicesHIGH
- Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran Intrusion at NCBJ Nuclear Centre, Void Manticore's Handala Persona Wipes 200,000 Stryker Devices, DragonForce Ransomware Disrupts Hazeldenes PoultryHIGH
- DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec ReferencesCRITICAL
- 2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)HIGH
- DragonForce Ransomware Abuses Microsoft Teams TURN Relays to Hide Backdoor.Turn C2 TrafficCRITICAL
- DragonForce 'Backdoor.Turn' Abuses Microsoft Teams TURN Relays to Conceal Ransomware C2 (Go RAT, BYOVD, CVE-2023-52271 / CVE-2025-61155 / CVE-2025-1055)HIGH
- DragonForce: White-Label Ransomware Cartel — Scattered Spider Partnership & MSP Supply Chain AttacksHIGH
Related CVEs
- CVE-2026-50752
- CVE-2026-50751
- CVE-2026-12569
- CVE-2026-0257
- CVE-2025-61155
- CVE-2025-30406
- CVE-2025-14611
- CVE-2025-11371
- CVE-2025-1055
- CVE-2025-0289
- CVE-2024-57728
- CVE-2024-57727
- CVE-2024-57726
- CVE-2024-53704
- CVE-2024-40766
- CVE-2024-27198
- CVE-2024-2617
- CVE-2024-21893
- CVE-2024-21887
- CVE-2024-21412
- CVE-2023-52271
- CVE-2023-4966
- CVE-2023-46805
- CVE-2023-3519
- CVE-2021-44228