DragonForce Ransomware: Vishing-Driven Help Desk Social Engineering Against UK Retailers (M&S, Co-op, Harrods)

DragonForce Ransomware (TL-2026-1647), also tracked as Operation targeting UK Retail 2025, is a high-severity ransomware operation, first published 2026-07-23. It is attributed to Scattered Spider with medium confidence, affects Marks & Spencer Retail IT / VMware ESXi e-commerce infrastructure, maps to 29 MITRE ATT&CK techniques (T1003, T1020, T1021), and is covered by 9 detection rules and 21 indicators of compromise.

Key facts for TL-2026-1647

Threat ID
TL-2026-1647
Also known as
Operation targeting UK Retail 2025, DragonForce UK Retail Wave
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
2026-07-23
Last reviewed
2026-07-23
Attribution
Scattered Spider
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
retail, ecommerce, consumer goods
Target regions
united kingdom
Detection rules
9
Indicators of compromise
21

Malware and tooling in DragonForce Ransomware

Malware and tooling: DragonForce, 3pktcrcbmssvrnwe5skburdwe2h3v6ibdnn5kbjqihsg6eu6s6b7ryqd.onion, AdFind - S0552, Cobalt Strike, Mimikatz, PSEXEC, Rclone - S1040, RogueKiller Anti-Rootkit Driver, SoftPerfect Network Scanner, SystemBC, dragonforxxbp3awc7mzs5dkswrua3znqyx5roefmi4smjrsdi22xwqd.onion, z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion

Scattered Spider affiliates operating under the DragonForce ransomware cartel compromised Marks & Spencer, Co-op, and Harrods by vishing IT help desks (including third-party contractor Tata Consultancy Services) into resetting employee credentials without proper verification, then used Mimikatz/NTDS.dit dumping, AdFind, RDP, PsExec and GPO abuse to disable EDR before deploying DragonForce ransomware against VMware ESXi hosts.

How DragonForce Ransomware works

Beginning as early as February 2025, Scattered Spider-affiliated actors leveraging the DragonForce ransomware-as-a-service/white-label 'cartel' model conducted a coordinated wave of intrusions against major UK retailers. The attackers used OSINT and harvested employee details to vish IT help desk staff — including at Marks & Spencer's outsourced help desk provider, Tata Consultancy Services (TCS) — into resetting multi-factor authentication and passwords for employee and privileged accounts without proper identity verification. Once inside, the actors exploited weak Active Directory configurations to escalate privileges, using Mimikatz for LSASS credential dumping and NTDS.dit extraction for offline hash cracking, AdFind for domain reconnaissance and trust discovery, and SoftPerfect Network Scanner for host/port enumeration. Lateral movement relied on living-off-the-land techniques: RDP, PsExec, SMB admin shares, and PowerShell remoting, supplemented by Cobalt Strike Beacon and a SystemBC SOCKS5 proxy implant for covert C2. Defense evasion included disabling EDR/antivirus via GPO manipulation and direct service tampering, BYOVD abuse of the RogueKiller Anti-Rootkit Driver to kill security processes at the kernel level, clearing Windows event logs (wevtutil cl System), and deleting Volume Shadow Copies via WMI/PowerShell to prevent recovery. Large volumes of data were exfiltrated via Rclone, wget, and cloud services (MEGA.nz, Amazon S3) prior to encryption, supporting a double-extortion model with data leaked on the DragonForce Tor leak site if ransom was unpaid. The DragonForce encryptor — derived from leaked LockBit 3.0 and Conti source code, using RSA+AES (ChaCha8 observed in some builds) — was deployed against Windows, Linux, and VMware ESXi hosts, encrypting entire virtual machine clusters supporting e-commerce and payment processing. At Marks & Spencer, this caused a roughly 46-day suspension of online orders, an estimated £3.8M/day in lost sales, and over £500M in market value erosion. Co-op suspended VPN access company-wide after detecting an intrusion attempt with initially limited back-office impact; Harrods publicly confirmed a cyberattack on 1 May 2025 with more limited operational disruption due to earlier containment. DragonForce operates a 'white-label' RaaS/cartel model (branded RansomBay) in which affiliates such as Scattered Spider retain roughly 80% of ransom proceeds while DragonForce takes a 20% cut and supplies leak-site and encryptor infrastructure. CISA, the FBI, and international partners (RCMP, ACSC/ASD, AFP, NCSC) issued an updated joint cybersecurity advisory on Scattered Spider on 29 July 2025 reflecting these evolved TTPs, including the shift from pure data-extortion to full DragonForce ransomware deployment.

MITRE ATT&CK techniques used in TL-2026-1647

Credential Access

T1003 OS Credential Dumping; T1621 Multi-Factor Authentication Request Generation

Exfiltration

T1020 Automated Exfiltration; T1567 Exfiltration Over Web Service

Lateral Movement

T1021 Remote Services

Discovery

T1046 Network Service Discovery; T1083 File and Directory Discovery; T1482 Domain Trust Discovery

Persistence

T1053 Scheduled Task/Job; T1098 Account Manipulation; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Defense Evasion

T1070 Indicator Removal; T1211 Exploitation for Stealth

Command and Control

T1071 Application Layer Protocol; T1090 Proxy

Initial Access

T1078 Valid Accounts; T1199 Trusted Relationship; T1566 Phishing

Privilege Escalation

T1078 Valid Accounts; T1134 Access Token Manipulation

defense-impairment

T1484 Domain or Tenant Policy Modification; T1685 Disable or Modify Tools

Impact

T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery

Resource Development

T1587 Develop Capabilities

Reconnaissance

T1589 Gather Victim Identity Information; T1593 Search Open Websites/Domains

Affected products and versions in DragonForce Ransomware

  • Marks & Spencer — Retail IT / VMware ESXi e-commerce infrastructure
    Vulnerable versions: Enterprise AD environment, help desk process pre-2025 hardening
    Fixed in: Post-incident help desk verification hardening (in progress)
  • Co-operative Group (Co-op) — Enterprise AD / VPN remote access infrastructure
    Vulnerable versions: Pre-incident VPN/help desk verification process
    Fixed in: Company-wide VPN suspension and remediation post-detection
  • Harrods — Retail enterprise IT / internet-facing infrastructure
    Vulnerable versions: Pre-incident network access controls
    Fixed in: Restricted internet access at stores/facilities post-containment
  • VMware — ESXi hypervisor
    Vulnerable versions: ESXi hosts without lockdown mode / weak vCenter credential hygiene
    Fixed in: N/A - operational hardening, not a vendor patch

Remediation for DragonForce Ransomware

Immediate actions

  • Enforce strict help desk identity-verification procedures (callback to a known-good number, manager approval, video verification) before any password reset or MFA re-enrollment
  • Suspend or tightly scope third-party/outsourced IT help desk privileges for password and MFA resets
  • Block or alert on the known DragonForce Tor leak-site .onion addresses at DNS/proxy egress where feasible
  • Enable Credential Guard and LSASS protected-process-light to blunt Mimikatz-style credential dumping
  • Deploy driver blocklisting / Microsoft vulnerable driver blocklist and enable HVCI to stop BYOVD EDR-killing (e.g. RogueKiller Anti-Rootkit Driver abuse)

Workarounds

  • Temporarily suspend all VPN/remote access pending help desk process hardening if active vishing campaigns are suspected
  • Rotate all domain admin and service account credentials and force NTDS.dit hash resets if compromise is suspected

Longer-term hardening

  • Move to FIDO2/phishing-resistant hardware MFA to resist SIM-swap, MFA-fatigue, and AiTM (Evilginx-style) attacks
  • Segment VMware ESXi management networks from general enterprise AD and enforce ESXi lockdown mode / vCenter MFA
  • Maintain immutable, offline/air-gapped backups with regular restore drills
  • Deploy EDR in tamper-resistant/anti-BYOVD mode across all endpoints and hypervisor management hosts
  • Establish a zero-trust identity model reducing standing privileged AD access and enforcing least privilege for help desk roles

Weaknesses (CWE) in DragonForce Ransomware

CWE-287, CWE-306, CWE-522

Timeline of DragonForce Ransomware

  • Scattered Spider-affiliated actors gain initial access to Marks & Spencer's environment, with dwell time later assessed to have begun as early as February 2025.
  • Attackers vish M&S's outsourced IT help desk (run by Tata Consultancy Services), impersonating employees using OSINT-gathered details to obtain password/MFA resets without proper verification.
  • DragonForce ransomware deployed against M&S's VMware ESXi hosts, encrypting virtual machines supporting e-commerce and payment processing systems.
  • Co-operative Group detects an intrusion attempt with initial limited impact on back-office and call-center services; suspends VPN access company-wide as a precaution.
  • M&S suspends online clothing and home orders amid ongoing ransomware remediation, beginning an approximately 46-day outage.
  • Harrods publicly confirms a cyberattack, restricting internet access at stores and facilities; earlier containment limits operational disruption.
  • Mitiga publishes 'Hackers in Aisle 5,' detailing the vishing-driven help desk social engineering and zero-trust failures behind the DragonForce UK retail attacks.
  • Picus Security publishes a technical breakdown of DragonForce TTPs used against M&S, Co-op, and Harrods, including tool usage (Mimikatz, AdFind, Cobalt Strike, SystemBC) and MITRE ATT&CK mapping.
  • M&S resumes taking online orders for select clothing lines after the extended outage caused by the ransomware attack.
  • CISA, FBI, RCMP, ACSC/ASD, AFP, and NCSC release an updated joint cybersecurity advisory on Scattered Spider reflecting its shift to full DragonForce ransomware deployment against enterprise victims.

Sources cited for DragonForce Ransomware

Threats related to DragonForce Ransomware

Detection coverage for TL-2026-1647

As of 2026-07-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1647 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats