DragonForce Ransomware: Vishing-Driven Help Desk Social Engineering Against UK Retailers (M&S, Co-op, Harrods)
DragonForce Ransomware (TL-2026-1647), also tracked as Operation targeting UK Retail 2025, is a high-severity ransomware operation, first published 2026-07-23. It is attributed to Scattered Spider with medium confidence, affects Marks & Spencer Retail IT / VMware ESXi e-commerce infrastructure, maps to 29 MITRE ATT&CK techniques (T1003, T1020, T1021), and is covered by 9 detection rules and 21 indicators of compromise.
Key facts for TL-2026-1647
- Threat ID
- TL-2026-1647
- Also known as
- Operation targeting UK Retail 2025, DragonForce UK Retail Wave
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-07-23
- Last reviewed
- 2026-07-23
- Attribution
- Scattered Spider
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- retail, ecommerce, consumer goods
- Target regions
- united kingdom
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in DragonForce Ransomware
Malware and tooling: DragonForce, 3pktcrcbmssvrnwe5skburdwe2h3v6ibdnn5kbjqihsg6eu6s6b7ryqd.onion, AdFind - S0552, Cobalt Strike, Mimikatz, PSEXEC, Rclone - S1040, RogueKiller Anti-Rootkit Driver, SoftPerfect Network Scanner, SystemBC, dragonforxxbp3awc7mzs5dkswrua3znqyx5roefmi4smjrsdi22xwqd.onion, z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion
Scattered Spider affiliates operating under the DragonForce ransomware cartel compromised Marks & Spencer, Co-op, and Harrods by vishing IT help desks (including third-party contractor Tata Consultancy Services) into resetting employee credentials without proper verification, then used Mimikatz/NTDS.dit dumping, AdFind, RDP, PsExec and GPO abuse to disable EDR before deploying DragonForce ransomware against VMware ESXi hosts.
How DragonForce Ransomware works
Beginning as early as February 2025, Scattered Spider-affiliated actors leveraging the DragonForce ransomware-as-a-service/white-label 'cartel' model conducted a coordinated wave of intrusions against major UK retailers. The attackers used OSINT and harvested employee details to vish IT help desk staff — including at Marks & Spencer's outsourced help desk provider, Tata Consultancy Services (TCS) — into resetting multi-factor authentication and passwords for employee and privileged accounts without proper identity verification. Once inside, the actors exploited weak Active Directory configurations to escalate privileges, using Mimikatz for LSASS credential dumping and NTDS.dit extraction for offline hash cracking, AdFind for domain reconnaissance and trust discovery, and SoftPerfect Network Scanner for host/port enumeration. Lateral movement relied on living-off-the-land techniques: RDP, PsExec, SMB admin shares, and PowerShell remoting, supplemented by Cobalt Strike Beacon and a SystemBC SOCKS5 proxy implant for covert C2. Defense evasion included disabling EDR/antivirus via GPO manipulation and direct service tampering, BYOVD abuse of the RogueKiller Anti-Rootkit Driver to kill security processes at the kernel level, clearing Windows event logs (wevtutil cl System), and deleting Volume Shadow Copies via WMI/PowerShell to prevent recovery. Large volumes of data were exfiltrated via Rclone, wget, and cloud services (MEGA.nz, Amazon S3) prior to encryption, supporting a double-extortion model with data leaked on the DragonForce Tor leak site if ransom was unpaid. The DragonForce encryptor — derived from leaked LockBit 3.0 and Conti source code, using RSA+AES (ChaCha8 observed in some builds) — was deployed against Windows, Linux, and VMware ESXi hosts, encrypting entire virtual machine clusters supporting e-commerce and payment processing. At Marks & Spencer, this caused a roughly 46-day suspension of online orders, an estimated £3.8M/day in lost sales, and over £500M in market value erosion. Co-op suspended VPN access company-wide after detecting an intrusion attempt with initially limited back-office impact; Harrods publicly confirmed a cyberattack on 1 May 2025 with more limited operational disruption due to earlier containment. DragonForce operates a 'white-label' RaaS/cartel model (branded RansomBay) in which affiliates such as Scattered Spider retain roughly 80% of ransom proceeds while DragonForce takes a 20% cut and supplies leak-site and encryptor infrastructure. CISA, the FBI, and international partners (RCMP, ACSC/ASD, AFP, NCSC) issued an updated joint cybersecurity advisory on Scattered Spider on 29 July 2025 reflecting these evolved TTPs, including the shift from pure data-extortion to full DragonForce ransomware deployment.
MITRE ATT&CK techniques used in TL-2026-1647
Credential Access
T1003 OS Credential Dumping; T1621 Multi-Factor Authentication Request Generation
Exfiltration
T1020 Automated Exfiltration; T1567 Exfiltration Over Web Service
Lateral Movement
Discovery
T1046 Network Service Discovery; T1083 File and Directory Discovery; T1482 Domain Trust Discovery
Persistence
T1053 Scheduled Task/Job; T1098 Account Manipulation; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Defense Evasion
T1070 Indicator Removal; T1211 Exploitation for Stealth
Command and Control
T1071 Application Layer Protocol; T1090 Proxy
Initial Access
T1078 Valid Accounts; T1199 Trusted Relationship; T1566 Phishing
Privilege Escalation
T1078 Valid Accounts; T1134 Access Token Manipulation
defense-impairment
T1484 Domain or Tenant Policy Modification; T1685 Disable or Modify Tools
Impact
T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery
Resource Development
Reconnaissance
T1589 Gather Victim Identity Information; T1593 Search Open Websites/Domains
Affected products and versions in DragonForce Ransomware
- Marks & Spencer — Retail IT / VMware ESXi e-commerce infrastructure
Vulnerable versions: Enterprise AD environment, help desk process pre-2025 hardening
Fixed in: Post-incident help desk verification hardening (in progress) - Co-operative Group (Co-op) — Enterprise AD / VPN remote access infrastructure
Vulnerable versions: Pre-incident VPN/help desk verification process
Fixed in: Company-wide VPN suspension and remediation post-detection - Harrods — Retail enterprise IT / internet-facing infrastructure
Vulnerable versions: Pre-incident network access controls
Fixed in: Restricted internet access at stores/facilities post-containment - VMware — ESXi hypervisor
Vulnerable versions: ESXi hosts without lockdown mode / weak vCenter credential hygiene
Fixed in: N/A - operational hardening, not a vendor patch
Remediation for DragonForce Ransomware
Immediate actions
- Enforce strict help desk identity-verification procedures (callback to a known-good number, manager approval, video verification) before any password reset or MFA re-enrollment
- Suspend or tightly scope third-party/outsourced IT help desk privileges for password and MFA resets
- Block or alert on the known DragonForce Tor leak-site .onion addresses at DNS/proxy egress where feasible
- Enable Credential Guard and LSASS protected-process-light to blunt Mimikatz-style credential dumping
- Deploy driver blocklisting / Microsoft vulnerable driver blocklist and enable HVCI to stop BYOVD EDR-killing (e.g. RogueKiller Anti-Rootkit Driver abuse)
Workarounds
- Temporarily suspend all VPN/remote access pending help desk process hardening if active vishing campaigns are suspected
- Rotate all domain admin and service account credentials and force NTDS.dit hash resets if compromise is suspected
Longer-term hardening
- Move to FIDO2/phishing-resistant hardware MFA to resist SIM-swap, MFA-fatigue, and AiTM (Evilginx-style) attacks
- Segment VMware ESXi management networks from general enterprise AD and enforce ESXi lockdown mode / vCenter MFA
- Maintain immutable, offline/air-gapped backups with regular restore drills
- Deploy EDR in tamper-resistant/anti-BYOVD mode across all endpoints and hypervisor management hosts
- Establish a zero-trust identity model reducing standing privileged AD access and enforcing least privilege for help desk roles
Weaknesses (CWE) in DragonForce Ransomware
CWE-287, CWE-306, CWE-522
Timeline of DragonForce Ransomware
- Scattered Spider-affiliated actors gain initial access to Marks & Spencer's environment, with dwell time later assessed to have begun as early as February 2025.
- Attackers vish M&S's outsourced IT help desk (run by Tata Consultancy Services), impersonating employees using OSINT-gathered details to obtain password/MFA resets without proper verification.
- DragonForce ransomware deployed against M&S's VMware ESXi hosts, encrypting virtual machines supporting e-commerce and payment processing systems.
- Co-operative Group detects an intrusion attempt with initial limited impact on back-office and call-center services; suspends VPN access company-wide as a precaution.
- M&S suspends online clothing and home orders amid ongoing ransomware remediation, beginning an approximately 46-day outage.
- Harrods publicly confirms a cyberattack, restricting internet access at stores and facilities; earlier containment limits operational disruption.
- Mitiga publishes 'Hackers in Aisle 5,' detailing the vishing-driven help desk social engineering and zero-trust failures behind the DragonForce UK retail attacks.
- Picus Security publishes a technical breakdown of DragonForce TTPs used against M&S, Co-op, and Harrods, including tool usage (Mimikatz, AdFind, Cobalt Strike, SystemBC) and MITRE ATT&CK mapping.
- M&S resumes taking online orders for select clothing lines after the extended outage caused by the ransomware attack.
- CISA, FBI, RCMP, ACSC/ASD, AFP, and NCSC release an updated joint cybersecurity advisory on Scattered Spider reflecting its shift to full DragonForce ransomware deployment against enterprise victims.
Sources cited for DragonForce Ransomware
- Hackers in Aisle 5: What DragonForce Taught Us About Zero Trust
- DragonForce Ransomware Hits Harrods, Marks and Spencer, Co-Op & Other UK Retailers
- Retail Under Fire: Inside the DragonForce Ransomware Attacks on Industry Giants
- DragonForce Ransomware Targets Major UK Retailers, Including Harrods, Marks & Spencer, and Co-Op
- UK Retail Cyber Attacks - Detailed Timeline
- Which UK retailers have been hit by cyber attacks in 2025?
- Marks & Spencer Breach: How A Ransomware Attack Crippled a UK Retail Giant
- Inside DragonForce, the Group Tied to M&S, Co-op and Harrods Hacks
- M&S ransomware hack: Service Desk & Active Directory security lessons
- CISA and Partners Release Updated Advisory on Scattered Spider Group
- Scattered Spider Ramps Up Ransomware In 2025 Cyber Alert
- Dark Web Profile: DragonForce Ransomware
- dragonforce Ransomware Group - TTPs, IOCs & Intelligence
- DragonForce Ransomware Group
Threats related to DragonForce Ransomware
- Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and Generative Identity Fraud Fuel Scattered Spider / ShinyHunters Campaigns
- Black Basta Ransomware Operation - Organizational Breakdown & 2025 Shutdown
- DevMan RaaS ("Funky Mantis") Centralizes Payload Builds, Victim Management, and Affiliate Payouts, Develops SCADA-Destructive Locker
- Ransom Cartel ransomware creator Maksim Silnikau sentenced to 16 years in federal prison
- The Gentlemen RaaS (Storm-2697) — Multi-Platform Ransomware-as-a-Service with BYOVD Defense Evasion and Self-Propagating Go Encryptor
- Q1 2026 Ransomware Landscape: Qilin Dominance, LockBit 5.0 Comeback, and FortiGate (CVE-2024-55591) / Oracle EBS (CVE-2025-61882) Mass Exploitation
Detection coverage for TL-2026-1647
As of 2026-07-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1647 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.