DragonForce: White-Label Ransomware Cartel — Scattered Spider Partnership & MSP Supply Chain Attacks
DragonForce: White-Label Ransomware Cartel — Scattered (TL-2026-0072) is a high-severity ransomware operation, first published 2026-02-12. It is attributed to DragonForce (Malaysia) with medium confidence, references 3 CVEs (CVE-2024-57727, CVE-2024-57728, CVE-2024-57726), maps to 52 MITRE ATT&CK techniques (T1003, T1005, T1018), and is covered by 12 detection rules and 29 indicators of compromise.
Key facts for TL-2026-0072
- Threat ID
- TL-2026-0072
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-02-12
- Last reviewed
- 2026-02-12
- Attribution
- DragonForce
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Malaysia
- Motivation
- FINANCIAL
- Target sectors
- Retail, Healthcare, Government, Technology, Financial Services, Managed Service Providers, Manufacturing
- Target regions
- United Kingdom, Europe, North America, Global
- Detection rules
- 12
- Indicators of compromise
- 29
Malware and tooling in DragonForce: White-Label Ransomware Cartel — Scattered
Malware and tooling: ScreenConnect, AnyDesk, TeamViewer, Splashtop — RMM tools deployed by Scattered Spider for persistence after social engineering initial access, White-label DragonForce encryptor deployed under different brand names (RansomBay first known subscriber), rentdrv2.sys — vulnerable driver exploited by DragonForce for BYOVD attacks to disable security products, rentdrv2.sys — vulnerable signed driver exploited by DragonForce as secondary BYOVD vector, truesight.sys — vulnerable driver exploited by DragonForce for BYOVD attacks to disable security products, truesight.sys — vulnerable signed driver exploited by DragonForce for BYOVD kernel access and EDR termination
DragonForce is an evolving ransomware operation that emerged in 2023 and rebranded in 2025 as a 'ransomware cartel' offering a white-label Ransomware-as-a-Service model where affiliates can deploy rebranded versions of the DragonForce encryptor under their own brand identity. The group takes 20% of paid ransoms (lower than the industry standard ~30%), offering affiliates infrastructure, negotiation tools, data storage, and encryptors for ESXi, NAS, BSD, and Windows — without the overhead of maintaining their own infrastructure. DragonForce's most significant development is its partnership with Scattered Spider, the English-speaking threat collective known for elite social engineering, SIM swapping, and MFA fatigue attacks. This partnership enabled devastating attacks on UK retailers Marks & Spencer (DragonForce ransomware deployed after Scattered Spider initial access) and Co-op (6.5M member records stolen, $107M operating loss). DragonForce also conducted an MSP supply chain attack via SimpleHelp RMM vulnerabilities (CVE-2024-57727/57728/57726), encrypting downstream customer systems. The group initially used the leaked LockBit 3.0 builder and later transitioned to modified Conti v3 source code, exploiting vulnerable drivers (truesight.sys, rentdrv2.sys) to disable security tools.
How DragonForce: White-Label Ransomware Cartel — Scattered works
DragonForce represents the EVOLUTION of the Ransomware-as-a-Service business model — from traditional affiliate programs to a 'cartel' marketplace where multiple ransomware brands operate under shared infrastructure. This is Ransomware-as-a-Platform.
FROM RAAS TO RANSOMWARE CARTEL: In March 2025, DragonForce announced its 'new direction': a white-label RaaS model where affiliates create 'their own brand under the auspices of an already proven partner.' The model works as a marketplace: - Affiliates choose to deploy attacks under the DragonForce brand OR their own custom brand - DragonForce provides infrastructure: encryptors, negotiation tools, data leak sites, storage - Affiliates don't manage infrastructure, develop malware, or handle negotiations - DragonForce takes 20% (vs industry standard ~30%), making it cost-competitive - The group aims to manage 'unlimited brands' across ESXi, NAS, BSD, and Windows - RansomBay is the first publicly known subscriber to the white-label model
SCATTERED SPIDER PARTNERSHIP: DragonForce's most consequential development is its partnership with Scattered Spider (UNC3944/Octo Tempest), an English-speaking threat collective known for: - Advanced social engineering: persona creation using OSINT, impersonation calls - SIM swapping and MFA fatigue/bombing to bypass authentication - Sophisticated initial access: credential theft, device registration for persistence - RMM tool deployment: ScreenConnect, AnyDesk, TeamViewer, Splashtop - AWS Systems Manager Inventory for lateral movement discovery - Data exfiltration to MEGA or Amazon S3 via ETL tools
This partnership creates a 'better together' model: Scattered Spider's elite social engineering provides initial access, and DragonForce's RaaS infrastructure handles encryption and extortion.
HIGH-PROFILE ATTACKS: - **Marks & Spencer (M&S):** Scattered Spider provided initial access via social engineering ('sophisticated impersonation attack'), followed by DragonForce ransomware deployment. Confirmed by M&S in July 2025. - **Co-op (UK retailer):** 6.5 million member records stolen. $107 million operating loss (£80M). Attack shut down systems and caused food shortages. - **MSP Supply Chain Attack:** Sophos investigated DragonForce breaching an MSP via SimpleHelp RMM vulnerabilities (CVE-2024-57727, CVE-2024-57728, CVE-2024-57726), then using SimpleHelp to enumerate customer environments, steal data, and deploy encryptors on downstream systems. One customer protected by Sophos; others encrypted. - **Ohio Lottery:** 538,000 individuals impacted.
TECHNICAL EVOLUTION: - Initially used leaked LockBit 3.0 builder for encryptor development - Transitioned to modified Conti v3 source code (addressing documented vulnerabilities) - Exploits vulnerable drivers (truesight.sys, rentdrv2.sys) for BYOVD attacks — disabling security products, shutting down protected processes - Fixed encryption vulnerabilities that were linked to Akira ransomware and documented in a Habr publication - Cross-platform: Windows, Linux, ESXi, NAS, BSD
OPERATIONAL PHILOSOPHY: DragonForce claims to follow a 'moral compass' — refusing to attack cancer or cardiac healthcare facilities ('We don't attack cancer patients or anything heart related... I didn't come here to kill people'). However, they target other healthcare organizations and have strict affiliate rules enforced through infrastructure control ('everything we run is on our servers').
STRATEGIC SIGNIFICANCE: DragonForce represents the 'cartelization' of cybercrime — specialized threat actors combining skills rather than competing. Scattered Spider provides elite social engineering; DragonForce provides infrastructure and malware. This collaborative model is more effective than either group operating alone. Secureworks notes the model 'may appeal to a wider range of affiliates and attract less technical threat actors,' lowering the barrier to entry for ransomware operations.
MITRE ATT&CK techniques used in TL-2026-0072
credential-access
T1003 OS Credential Dumping; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores; T1621 Multi-Factor Authentication Request Generation
collection
T1005 Data from Local System; T1039 Data from Network Shared Drive; T1074 Data Staged; T1213 Data from Information Repositories
discovery
T1018 Remote System Discovery; T1046 Network Service Discovery; T1069 Permission Groups Discovery; T1082 System Information Discovery; T1087 Account Discovery; T1135 Network Share Discovery; T1526 Cloud Service Discovery; T1580 Cloud Infrastructure Discovery
lateral-movement
T1021 Remote Services; T1570 Lateral Tool Transfer
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1078 Valid Accounts; T1211 Exploitation for Stealth
execution
T1059 Command and Scripting Interpreter; T1569 System Services
privilege-escalation
T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism
command-and-control
T1071 Application Layer Protocol; T1090 Proxy; T1219 Remote Access Tools
persistence
T1098 Account Manipulation; T1133 External Remote Services; T1543 Create or Modify System Process
initial-access
T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1199 Trusted Relationship; T1566 Phishing
impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1498 Network Denial of Service; T1529 System Shutdown/Reboot
exfiltration
T1537 Transfer Data to Cloud Account; T1567 Exfiltration Over Web Service
resource-development
T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities
reconnaissance
T1589 Gather Victim Identity Information; T1591 Gather Victim Org Information; T1596 Search Open Technical Databases
defense-impairment
Remediation for DragonForce: White-Label Ransomware Cartel — Scattered
Patches
- CVE-2024-57727 — SimpleHelp path traversal vulnerability
- CVE-2024-57728 — SimpleHelp arbitrary file upload
- CVE-2024-57726 — SimpleHelp privilege escalation
Immediate actions
- Patch SimpleHelp RMM against CVE-2024-57727, CVE-2024-57728, CVE-2024-57726 — DragonForce actively exploits these for MSP supply chain attacks
- Implement phishing-resistant MFA (FIDO2/hardware keys) — Scattered Spider defeats SMS/app-based MFA via SIM swapping and MFA fatigue
- Monitor for unauthorized RMM tool installations (ScreenConnect, AnyDesk, TeamViewer, Splashtop) — Scattered Spider's persistence mechanism
- Block or monitor vulnerable drivers truesight.sys and rentdrv2.sys — DragonForce uses BYOVD to disable security tools
- Audit MSP access to your environment — restrict SimpleHelp and other RMM tools to minimum required scope
Workarounds
- Restrict external access to SimpleHelp instances — place behind VPN or zero-trust gateway
- Implement conditional access policies blocking MFA registrations from unexpected locations — prevents Scattered Spider device registration
- Monitor AWS Systems Manager Inventory usage for unauthorized asset discovery — Scattered Spider uses this for lateral movement
- Deploy canary accounts and honeytokens specifically for social engineering detection
Longer-term hardening
- Implement identity verification for helpdesk/service desk requests — Scattered Spider impersonates employees to reset credentials and bypass MFA
- Deploy EDR with driver load monitoring — detect BYOVD attacks (truesight.sys, rentdrv2.sys) before security tools are disabled
- Segment MSP access from production environments — MSP supply chain attacks provide access to all downstream customers
- Establish MSP security requirements and audit compliance — SimpleHelp vulnerabilities were the entry point for downstream customer compromise
- Monitor for data exfiltration to MEGA and Amazon S3 — Scattered Spider's confirmed exfiltration destinations
CVEs associated with DragonForce: White-Label Ransomware Cartel — Scattered
Weaknesses (CWE) in DragonForce: White-Label Ransomware Cartel — Scattered
CWE-22, CWE-269, CWE-434, CWE-287
Timeline of DragonForce: White-Label Ransomware Cartel — Scattered
- DragonForce ransomware operation emerges, initially using the leaked LockBit 3.0 builder to create encryption tools. Begins recruiting affiliates through underground cybercrime platforms. Source: Acronis TRU/BleepingComputer
- DragonForce transitions from LockBit 3.0 builder to modified Conti v3 source code, addressing encryption vulnerabilities documented in Habr publication. Implements vulnerable driver exploitation (truesight.sys, rentdrv2.sys) for BYOVD attacks. Source: Acronis TRU
- DragonForce ransomware attack on Ohio Lottery impacts 538,000 individuals, demonstrating growing operational reach. Source: BleepingComputer
- DragonForce announces 'new direction' — rebrands as 'ransomware cartel' offering white-label RaaS model. Affiliates create their own brand under DragonForce infrastructure. 20% commission (vs 30% industry standard). Aims to manage 'unlimited brands' across ESXi, NAS, BSD, Windows. Source: BleepingComputer/Secureworks
- Marks & Spencer (M&S) breached via Scattered Spider social engineering ('sophisticated impersonation attack') followed by DragonForce ransomware deployment. Major UK retail disruption. Source: BleepingComputer
- UK retailer Co-op breached by DragonForce via Scattered Spider tactics. 6.5 million member records stolen. Systems shut down causing food shortages in grocery stores. Source: BleepingComputer
- Sophos reports DragonForce breaching MSP via SimpleHelp RMM vulnerabilities (CVE-2024-57727/57728/57726), then using SimpleHelp to steal data and deploy encryptors on downstream customer systems. Source: Sophos/BleepingComputer
- M&S officially confirms social engineering was the initial access vector — 'sophisticated impersonation attack' by Scattered Spider enabled DragonForce deployment. Source: BleepingComputer
- Co-op reveals $107 million (£80M) operating loss from DragonForce/Scattered Spider attack in interim financial results. Source: BleepingComputer
- Acronis TRU publishes deep-dive analysis of DragonForce and Scattered Spider connection — documents LockBit 3.0 → Conti v3 code evolution, BYOVD driver exploitation (truesight.sys, rentdrv2.sys), and cartel recruitment strategy. Source: Acronis TRU/BleepingComputer
- As of 2026-05-29, DragonForce remains highly active — ransomware.live shows 560 victims with the newest posted this very day and portals live May 30, and it was recently the top group by volume. CVE-2024-57727 (SimpleHelp) is patched but still in CISA KEV and exploited; partner Scattered Spider rebranded into the SLH alliance rather than being shut down.
Sources cited for DragonForce: White-Label Ransomware Cartel — Scattered
- BleepingComputer: DragonForce expands ransomware model with white-label branding scheme
- BleepingComputer/Acronis: Deep dive into DragonForce and Scattered Spider connection
- BleepingComputer: DragonForce abuses SimpleHelp in MSP supply chain attack
- Sophos: DragonForce targets SimpleHelp vulnerabilities for MSP customer attacks
- Secureworks: Ransomware Groups Evolve Affiliate Models
- BleepingComputer: M&S confirms social engineering led to DragonForce ransomware attack
- BleepingComputer: Co-op $107M loss from Scattered Spider/DragonForce attack
Threats related to DragonForce: White-Label Ransomware Cartel — Scattered
- Storm-1175 Medusa Ransomware Zero-Day Exploitation Campaign (CVE-2026-23760, CVE-2025-10035)
- INC Ransom Affiliate Network Targeting Pacific Critical Infrastructure (AU/NZ/Tonga Joint Advisory)
- Black Basta Ransomware: Internal Chat Leaks Expose $100M+ RaaS Operation — Conti Successor Unmasked
- DeadLock Ransomware: Smart Contracts for Malicious Purposes — Blockchain-Automated Ransom Operations
- The Gentlemen Ransomware: Emerging Multi-Region Enterprise Threat — 80+ Victims Across 30+ Countries Since September 2025
- ShadowSyndicate: Infrastructure-Sharing RaaS Affiliate Linked to 7+ Ransomware Families
Detection coverage for TL-2026-0072
As of 2026-02-12, Threadlinqs Intelligence publishes 12 detection rule(s) for TL-2026-0072 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.