DragonForce: White-Label Ransomware Cartel — Scattered Spider Partnership & MSP Supply Chain Attacks — Threadlinqs Intelligence
As of 2026-05-30, DragonForce: White-Label Ransomware Cartel — Scattered Spider Partnership & MSP Supply Chain Attacks is a high-severity ransomware threat attributed to DragonForce (Malaysia), tracked by Threadlinqs Intelligence with 12 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 29 indicators of compromise.
Threat ID: TL-2026-0072 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: DragonForce · Malaysia · FINANCIAL
DragonForce is an evolving ransomware operation that emerged in 2023 and rebranded in 2025 as a 'ransomware cartel' offering a white-label Ransomware-as-a-Service model where affiliates can deploy
DragonForce represents the EVOLUTION of the Ransomware-as-a-Service business model — from traditional affiliate programs to a 'cartel' marketplace where multiple ransomware brands operate under shared infrastructure. This is Ransomware-as-a-Platform.
FROM RAAS TO RANSOMWARE CARTEL:
In March 2025, DragonForce announced its 'new direction': a white-label RaaS model where affiliates create 'their own brand under the auspices of an already proven partner.' The model works as a marketplace:
- Affiliates choose to deploy attacks under the DragonForce brand OR their own custom brand
- DragonForce provides infrastructure: encryptors, negotiation tools, data leak sites, storage
- Affiliates don't manage infrastructure, develop malware, or handle negotiations
- DragonForce takes 20% (vs industry standard ~30%), making it cost-competitive
- The group aims to manage 'unlimited brands' across ESXi, NAS, BSD, and Windows
- RansomBay is the first publicly known subscriber to the white-label model
SCATTERED SPIDER PARTNERSHIP:
DragonForce's most consequential development is its partnership with Scattered Spider (UNC3944/Octo Tempest), an English-speaking threat collective known for:
- Advanced social engineering: persona creation using OSINT, impersonation calls
- SIM swapping and MFA fatigue/bombing to bypass authentication
- Sophisticated initial access: credential theft, device registration for persistence
- RMM tool deployment: ScreenConnect, AnyDesk, TeamViewer, Splashtop
- AWS Systems Manager Inventory for lateral movement discovery
- Data exfiltration to MEGA or Amazon S3 via ETL tools
This partnership creates a 'better together' model: Scattered Spider's elite social engineering provides initial access, and DragonForce's RaaS infrastructure handles encryption and extortion.
HIGH-PROFILE ATTACKS:
- **Marks & Spencer (M&S):** Scattered Spider provided initial access via social engineering ('sophisticated impersonation attack'), followed by DragonForce ransomware deployment. Confirmed by M&S in July 2025.
- **Co-op (UK retailer):** 6.5 million member records stolen. $107 million operating loss (£80M). Attack shut down systems and caused food shortages.
- **MSP Supply Chain Attack:** Sophos investigated DragonForce breaching an MSP via SimpleHelp RMM vulnerabilities (CVE-2024-57727, CVE-2024-57728, CVE-2024-57726), then using SimpleHelp to enumerate customer environments, steal data, and deploy encryptors on downstream systems. One customer protected by Sophos; others encrypted.
- **Ohio Lottery:** 538,000 individuals impacted.
TECHNICAL EVOLUTION:
- Initially used leaked LockBit 3.0 builder for encryptor development
- Transitioned to modified Conti v3 source code (addressing documented vulnerabilities)
- Exploits vulnerable drivers (truesight.sys, rentdrv2.sys) for BYOVD attacks — disabling security products, shutting down protected processes
- Fixed encryption vulnerabilities that were linked to Akira ransomware and documented in a Habr publication
- Cross-platform: Windows, Linux, ESXi, NAS, BSD
OPERATIONAL PHILOSOPHY:
DragonForce claims to follow a 'moral compass' — refusing to attack cancer or cardiac healthcare facilities ('We don't attack cancer patients or anything heart related... I didn't come here to kill people'). However, they target other healthcare organizations and have strict affiliate rules enforced through infrastructure control ('everything we run is on our servers').
STRATEGIC SIGNIFICANCE:
DragonForce represents the 'cartelization' of cybercrime — specialized threat actors combining skills rather than competing. Scattered Spider provides elite social engineering; DragonForce provides infrastructure and malware. This collaborative model is more effective than either group operating alone. Secureworks notes the model 'may appeal to a wider range of affiliates and attract less technical threat actors,' lowering the barrier to entry for ransomware operations.
Weaknesses (CWE)
CWE-22, CWE-269, CWE-434, CWE-287
Target sectors: Retail, Healthcare, Government, Technology, Financial Services, Managed Service Providers, Manufacturing
Target regions: United Kingdom, Europe, North America, Global
Detections & IOCs
As of 2026-07-26, this threat has 12 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 29 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, CVE-2024-57727, CVE-2024-57728, CVE-2024-57726, T1589, T1591, T1588, T1566, T1190, T1195, T1078, T1059, T1133, T1098