DragonForce: White-Label Ransomware Cartel — Scattered Spider Partnership & MSP Supply Chain Attacks

DragonForce: White-Label Ransomware Cartel — Scattered (TL-2026-0072) is a high-severity ransomware operation, first published 2026-02-12. It is attributed to DragonForce (Malaysia) with medium confidence, references 3 CVEs (CVE-2024-57727, CVE-2024-57728, CVE-2024-57726), maps to 52 MITRE ATT&CK techniques (T1003, T1005, T1018), and is covered by 12 detection rules and 29 indicators of compromise.

Key facts for TL-2026-0072

Threat ID
TL-2026-0072
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
2026-02-12
Last reviewed
2026-02-12
Attribution
DragonForce
Attribution confidence
MEDIUM
Nation-state nexus
Malaysia
Motivation
FINANCIAL
Target sectors
Retail, Healthcare, Government, Technology, Financial Services, Managed Service Providers, Manufacturing
Target regions
United Kingdom, Europe, North America, Global
Detection rules
12
Indicators of compromise
29

Malware and tooling in DragonForce: White-Label Ransomware Cartel — Scattered

Malware and tooling: ScreenConnect, AnyDesk, TeamViewer, Splashtop — RMM tools deployed by Scattered Spider for persistence after social engineering initial access, White-label DragonForce encryptor deployed under different brand names (RansomBay first known subscriber), rentdrv2.sys — vulnerable driver exploited by DragonForce for BYOVD attacks to disable security products, rentdrv2.sys — vulnerable signed driver exploited by DragonForce as secondary BYOVD vector, truesight.sys — vulnerable driver exploited by DragonForce for BYOVD attacks to disable security products, truesight.sys — vulnerable signed driver exploited by DragonForce for BYOVD kernel access and EDR termination

DragonForce is an evolving ransomware operation that emerged in 2023 and rebranded in 2025 as a 'ransomware cartel' offering a white-label Ransomware-as-a-Service model where affiliates can deploy rebranded versions of the DragonForce encryptor under their own brand identity. The group takes 20% of paid ransoms (lower than the industry standard ~30%), offering affiliates infrastructure, negotiation tools, data storage, and encryptors for ESXi, NAS, BSD, and Windows — without the overhead of maintaining their own infrastructure. DragonForce's most significant development is its partnership with Scattered Spider, the English-speaking threat collective known for elite social engineering, SIM swapping, and MFA fatigue attacks. This partnership enabled devastating attacks on UK retailers Marks & Spencer (DragonForce ransomware deployed after Scattered Spider initial access) and Co-op (6.5M member records stolen, $107M operating loss). DragonForce also conducted an MSP supply chain attack via SimpleHelp RMM vulnerabilities (CVE-2024-57727/57728/57726), encrypting downstream customer systems. The group initially used the leaked LockBit 3.0 builder and later transitioned to modified Conti v3 source code, exploiting vulnerable drivers (truesight.sys, rentdrv2.sys) to disable security tools.

How DragonForce: White-Label Ransomware Cartel — Scattered works

DragonForce represents the EVOLUTION of the Ransomware-as-a-Service business model — from traditional affiliate programs to a 'cartel' marketplace where multiple ransomware brands operate under shared infrastructure. This is Ransomware-as-a-Platform.

FROM RAAS TO RANSOMWARE CARTEL: In March 2025, DragonForce announced its 'new direction': a white-label RaaS model where affiliates create 'their own brand under the auspices of an already proven partner.' The model works as a marketplace: - Affiliates choose to deploy attacks under the DragonForce brand OR their own custom brand - DragonForce provides infrastructure: encryptors, negotiation tools, data leak sites, storage - Affiliates don't manage infrastructure, develop malware, or handle negotiations - DragonForce takes 20% (vs industry standard ~30%), making it cost-competitive - The group aims to manage 'unlimited brands' across ESXi, NAS, BSD, and Windows - RansomBay is the first publicly known subscriber to the white-label model

SCATTERED SPIDER PARTNERSHIP: DragonForce's most consequential development is its partnership with Scattered Spider (UNC3944/Octo Tempest), an English-speaking threat collective known for: - Advanced social engineering: persona creation using OSINT, impersonation calls - SIM swapping and MFA fatigue/bombing to bypass authentication - Sophisticated initial access: credential theft, device registration for persistence - RMM tool deployment: ScreenConnect, AnyDesk, TeamViewer, Splashtop - AWS Systems Manager Inventory for lateral movement discovery - Data exfiltration to MEGA or Amazon S3 via ETL tools

This partnership creates a 'better together' model: Scattered Spider's elite social engineering provides initial access, and DragonForce's RaaS infrastructure handles encryption and extortion.

HIGH-PROFILE ATTACKS: - **Marks & Spencer (M&S):** Scattered Spider provided initial access via social engineering ('sophisticated impersonation attack'), followed by DragonForce ransomware deployment. Confirmed by M&S in July 2025. - **Co-op (UK retailer):** 6.5 million member records stolen. $107 million operating loss (£80M). Attack shut down systems and caused food shortages. - **MSP Supply Chain Attack:** Sophos investigated DragonForce breaching an MSP via SimpleHelp RMM vulnerabilities (CVE-2024-57727, CVE-2024-57728, CVE-2024-57726), then using SimpleHelp to enumerate customer environments, steal data, and deploy encryptors on downstream systems. One customer protected by Sophos; others encrypted. - **Ohio Lottery:** 538,000 individuals impacted.

TECHNICAL EVOLUTION: - Initially used leaked LockBit 3.0 builder for encryptor development - Transitioned to modified Conti v3 source code (addressing documented vulnerabilities) - Exploits vulnerable drivers (truesight.sys, rentdrv2.sys) for BYOVD attacks — disabling security products, shutting down protected processes - Fixed encryption vulnerabilities that were linked to Akira ransomware and documented in a Habr publication - Cross-platform: Windows, Linux, ESXi, NAS, BSD

OPERATIONAL PHILOSOPHY: DragonForce claims to follow a 'moral compass' — refusing to attack cancer or cardiac healthcare facilities ('We don't attack cancer patients or anything heart related... I didn't come here to kill people'). However, they target other healthcare organizations and have strict affiliate rules enforced through infrastructure control ('everything we run is on our servers').

STRATEGIC SIGNIFICANCE: DragonForce represents the 'cartelization' of cybercrime — specialized threat actors combining skills rather than competing. Scattered Spider provides elite social engineering; DragonForce provides infrastructure and malware. This collaborative model is more effective than either group operating alone. Secureworks notes the model 'may appeal to a wider range of affiliates and attract less technical threat actors,' lowering the barrier to entry for ransomware operations.

MITRE ATT&CK techniques used in TL-2026-0072

credential-access

T1003 OS Credential Dumping; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores; T1621 Multi-Factor Authentication Request Generation

collection

T1005 Data from Local System; T1039 Data from Network Shared Drive; T1074 Data Staged; T1213 Data from Information Repositories

discovery

T1018 Remote System Discovery; T1046 Network Service Discovery; T1069 Permission Groups Discovery; T1082 System Information Discovery; T1087 Account Discovery; T1135 Network Share Discovery; T1526 Cloud Service Discovery; T1580 Cloud Infrastructure Discovery

lateral-movement

T1021 Remote Services; T1570 Lateral Tool Transfer

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1078 Valid Accounts; T1211 Exploitation for Stealth

execution

T1059 Command and Scripting Interpreter; T1569 System Services

privilege-escalation

T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism

command-and-control

T1071 Application Layer Protocol; T1090 Proxy; T1219 Remote Access Tools

persistence

T1098 Account Manipulation; T1133 External Remote Services; T1543 Create or Modify System Process

initial-access

T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1199 Trusted Relationship; T1566 Phishing

impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1498 Network Denial of Service; T1529 System Shutdown/Reboot

exfiltration

T1537 Transfer Data to Cloud Account; T1567 Exfiltration Over Web Service

resource-development

T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities

reconnaissance

T1589 Gather Victim Identity Information; T1591 Gather Victim Org Information; T1596 Search Open Technical Databases

defense-impairment

T1685 Disable or Modify Tools

Remediation for DragonForce: White-Label Ransomware Cartel — Scattered

Patches

  • CVE-2024-57727 — SimpleHelp path traversal vulnerability
  • CVE-2024-57728 — SimpleHelp arbitrary file upload
  • CVE-2024-57726 — SimpleHelp privilege escalation

Immediate actions

  • Patch SimpleHelp RMM against CVE-2024-57727, CVE-2024-57728, CVE-2024-57726 — DragonForce actively exploits these for MSP supply chain attacks
  • Implement phishing-resistant MFA (FIDO2/hardware keys) — Scattered Spider defeats SMS/app-based MFA via SIM swapping and MFA fatigue
  • Monitor for unauthorized RMM tool installations (ScreenConnect, AnyDesk, TeamViewer, Splashtop) — Scattered Spider's persistence mechanism
  • Block or monitor vulnerable drivers truesight.sys and rentdrv2.sys — DragonForce uses BYOVD to disable security tools
  • Audit MSP access to your environment — restrict SimpleHelp and other RMM tools to minimum required scope

Workarounds

  • Restrict external access to SimpleHelp instances — place behind VPN or zero-trust gateway
  • Implement conditional access policies blocking MFA registrations from unexpected locations — prevents Scattered Spider device registration
  • Monitor AWS Systems Manager Inventory usage for unauthorized asset discovery — Scattered Spider uses this for lateral movement
  • Deploy canary accounts and honeytokens specifically for social engineering detection

Longer-term hardening

  • Implement identity verification for helpdesk/service desk requests — Scattered Spider impersonates employees to reset credentials and bypass MFA
  • Deploy EDR with driver load monitoring — detect BYOVD attacks (truesight.sys, rentdrv2.sys) before security tools are disabled
  • Segment MSP access from production environments — MSP supply chain attacks provide access to all downstream customers
  • Establish MSP security requirements and audit compliance — SimpleHelp vulnerabilities were the entry point for downstream customer compromise
  • Monitor for data exfiltration to MEGA and Amazon S3 — Scattered Spider's confirmed exfiltration destinations

CVEs associated with DragonForce: White-Label Ransomware Cartel — Scattered

CVE-2024-57727, CVE-2024-57728, CVE-2024-57726

Weaknesses (CWE) in DragonForce: White-Label Ransomware Cartel — Scattered

CWE-22, CWE-269, CWE-434, CWE-287

Timeline of DragonForce: White-Label Ransomware Cartel — Scattered

  • DragonForce ransomware operation emerges, initially using the leaked LockBit 3.0 builder to create encryption tools. Begins recruiting affiliates through underground cybercrime platforms. Source: Acronis TRU/BleepingComputer
  • DragonForce transitions from LockBit 3.0 builder to modified Conti v3 source code, addressing encryption vulnerabilities documented in Habr publication. Implements vulnerable driver exploitation (truesight.sys, rentdrv2.sys) for BYOVD attacks. Source: Acronis TRU
  • DragonForce ransomware attack on Ohio Lottery impacts 538,000 individuals, demonstrating growing operational reach. Source: BleepingComputer
  • DragonForce announces 'new direction' — rebrands as 'ransomware cartel' offering white-label RaaS model. Affiliates create their own brand under DragonForce infrastructure. 20% commission (vs 30% industry standard). Aims to manage 'unlimited brands' across ESXi, NAS, BSD, Windows. Source: BleepingComputer/Secureworks
  • Marks & Spencer (M&S) breached via Scattered Spider social engineering ('sophisticated impersonation attack') followed by DragonForce ransomware deployment. Major UK retail disruption. Source: BleepingComputer
  • UK retailer Co-op breached by DragonForce via Scattered Spider tactics. 6.5 million member records stolen. Systems shut down causing food shortages in grocery stores. Source: BleepingComputer
  • Sophos reports DragonForce breaching MSP via SimpleHelp RMM vulnerabilities (CVE-2024-57727/57728/57726), then using SimpleHelp to steal data and deploy encryptors on downstream customer systems. Source: Sophos/BleepingComputer
  • M&S officially confirms social engineering was the initial access vector — 'sophisticated impersonation attack' by Scattered Spider enabled DragonForce deployment. Source: BleepingComputer
  • Co-op reveals $107 million (£80M) operating loss from DragonForce/Scattered Spider attack in interim financial results. Source: BleepingComputer
  • Acronis TRU publishes deep-dive analysis of DragonForce and Scattered Spider connection — documents LockBit 3.0 → Conti v3 code evolution, BYOVD driver exploitation (truesight.sys, rentdrv2.sys), and cartel recruitment strategy. Source: Acronis TRU/BleepingComputer
  • As of 2026-05-29, DragonForce remains highly active — ransomware.live shows 560 victims with the newest posted this very day and portals live May 30, and it was recently the top group by volume. CVE-2024-57727 (SimpleHelp) is patched but still in CISA KEV and exploited; partner Scattered Spider rebranded into the SLH alliance rather than being shut down.

Sources cited for DragonForce: White-Label Ransomware Cartel — Scattered

Threats related to DragonForce: White-Label Ransomware Cartel — Scattered

Detection coverage for TL-2026-0072

As of 2026-02-12, Threadlinqs Intelligence publishes 12 detection rule(s) for TL-2026-0072 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats