DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec References — Threadlinqs Intelligence
As of 2026-09-06, DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec References is a critical-severity ransomware threat attributed to DragonForce (MY), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-2364 · Severity: CRITICAL · Status: ACTIVE · Category: RANSOMWARE
Attribution: DragonForce · MY · FINANCIAL
The DragonForce ransomware cartel posted RubberMill, Inc. (North Carolina-based ISO 9001:2015/WOSB/WBENC-certified contract manufacturer serving appliance, HVAC, automotive, and defense sectors) on
DragonForce is a prolific Ransomware-as-a-Service (RaaS) cartel that first emerged in August 2023 from Pro-Palestine hacktivist roots before pivoting to a financially motivated multi-extortion model. The group initially built payloads using the leaked LockBit 3.0 (Black) builder, then transitioned to a bespoke Conti V3-derived codebase by July 2024. DragonForce ransomware uses ChaCha8 symmetric encryption with per-file 32-byte keys and 8-byte nonces, wrapped in RSA-4096 asymmetric encryption. A 537-byte footer is appended to each encrypted file containing the RSA ciphertext, encryption mode flag, and original file size. The ransomware encrypts files with a .dragonforce_encrypted extension and drops readme.txt ransom notes.
The attack on RubberMill — a women-owned small business (WOSB), ISO 9001:2015-certified contract manufacturer in Liberty, North Carolina — reflects DragonForce affiliates' targeting of the US manufacturing and defense supply chain. RubberMill manufactures custom non-metallic components (molded rubber, die-cut gaskets, foam insulation, laminates) for OEMs across the appliance, HVAC, automotive, heavy equipment, and defense sectors. The company lists compliance with military specifications (Mil-Spec) and holds certifications including ISO 9001:2015, WBENC, and WOSB.
DragonForce affiliates achieve initial access through phishing campaigns, exploitation of known CVEs (including CVE-2021-44228 Log4Shell, CVE-2023-46805/CVE-2024-21887 Ivanti Connect Secure vulnerabilities, and CVE-2024-21412 SmartScreen bypass), credential stuffing against RDP services, and trusted relationship abuse — including leveraging leftover remote management software from prior hosting providers. Post-exploitation involves deploying Cobalt Strike beacons for C2 and lateral movement, SystemBC SOCKS5 backdoor for persistent proxy access, AnyDesk and SimpleHelp for remote interactive access, and the BYOVD technique using Truesight.sys, RentDrv.sys, and KslD.sys vulnerable drivers to terminate EDR/XDR processes via DeviceIoControl calls.
Data exfiltration is performed using a renamed copy of the open-source Restic backup tool (deployed as winupdate.exe) which uploads data to attacker-controlled AWS S3 buckets hosted on wasabisys.com. Exfiltration also occurs via MEGA cloud storage, SFTP, and WebDAV transfers to remote infrastructure. The exfiltration tool employs GoLang-based deduplicated encrypted transfer optimized for bulk data. FileSeek.exe is used to inventory target files before exfiltration. In more recent intrusions (December 2025), DragonForce affiliates have employed Backdoor.Turn — a backdoor that establishes persistence as the TeamsMediaRelay Windows service and communicates via QUIC protocol through Microsoft Teams TURN relay infrastructure to blend in with legitimate Microsoft 365 traffic.
The RubberMill data dump comprehensively spans the entire business: a full 146 GB disk image providing forensic-level system access, employee PII including SSNs and tax forms, credit card data running multiple records, corporate password stores (AES PASSWORDS.xlsx), a 487 MB Outlook PST email archive, a 38 MB sales database (.mdb), 3000+ CAD files in .dxf/.stp/.dwg formats with customer part numbers (7J314, K2A31, K7K11, V1324), C-TPAT and NAFTA compliance certifications, Conflict Minerals Reporting, a Supplier Quality Assurance Manual, and defense-relevant Mil-Spec documentation. The leak group characterizes the haul as containing 'a full cross-section of the business: from passwords and SSNs to automotive OEM drawings and military specifications.' No ransom demand amount was disclosed, but the posting on the dedicated leak site indicates that ransom negotiations failed or were refused.
DragonForce operates an extensive affiliate ecosystem (the 'Ransomware Cartel' model) offering infrastructure, malware, and support services including DDoS, spam campaigns, and cold-calling victim executives as 'pressure-as-a-service.' Affiliates retain up
Target sectors: manufacturing, defense-industrial-base, automotive, aerospace, heavy-equipment
Target regions: North America, united states of america
Timeline
- DragonForce ransomware group first emerges, initially operating out of Malaysia with Pro-Palestine hacktivist roots before pivoting to financially motivated operations
- DragonForce transitions from LockBit 3.0/Black builder to bespoke Conti V3-derived codebase, introducing ChaCha8 encryption and BYOVD capability via Truesight.sys/RentDrv.sys
- DragonForce launches white-label RaaS service and RansomBay dedicated leak site, expanding affiliate ecosystem with 'pressure-as-a-service' offerings including DDoS, spam campaigns, and cold-calling victim executives
- Estimated date of DragonForce ransomware attack on RubberMill, Inc. — initial access (phishing, RDP credential stuffing, or exploited CVE) leading to Cobalt Strike deployment, SystemBC backdoor installation, and network reconnaissance
- DragonForce affiliates deploy Mimikatz for LSASS credential dumping and access Veeam backup credentials via Get-VeeamCreds.ps1; extract AES PASSWORDS.xlsx and APWDxx credential stores from file servers
- AnyDesk installed for persistent remote access; SystemBC backdoor deployed for SOCKS5 proxy C2; Cobalt Strike beacon established on domain controllers for lateral movement
- Exfiltration begins using renamed Restic backup tool (winupdate.exe) uploading ~340GB of data to attacker-controlled AWS S3 buckets on wasabisys.com; data includes 146GB disk image, 487MB PST email archive, 38MB sales database, 3,000+ CAD files, and employee PII with SSNs
- Ransomware encryptor (df.exe from C:\PerfLogs\) deployed across network; BYOVD driver (KslD.sys) loaded to terminate EDR/XDR processes; Volume Shadow Copies deleted via vssadmin.exe; Windows Event Logs cleared
- Ransom notes (readme.txt) dropped on affected systems demanding payment; negotiation window opens through DragonForce Tox ID and Session ID contacts
- DragonForce posts RubberMill data on DragonLeaks Tor leak site after ransom negotiations fail or are refused; full data dump of ~296K files / 340+ GB published including PII (SSNs, tax forms, employee records), credit card data, credentials, defense Mil-Spec CAD files, C-TPAT/NAFTA documentation, and sales databases
Detections & IOCs
As of 2026-09-07, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
RANSOMWARE, CRITICAL, threat intelligence, cybersecurity, CVE-2021-44228, CVE-2023-46805, CVE-2024-21412, CVE-2024-21887, CVE-2024-21893, CVE-2025-0289, T1566, T1190, T1078, T1199, T1059, T1204, T1543, T1685, T1055, T1574