DragonForce — Ransomware Profile

DragonForce is a ransomware-as-a-service operation first observed in August 2023, initially deploying a variant of the leaked LockBit 3.0 builder and later a customised Conti V3 payload, and rebranding as a ransomware "cartel" in 2025. It is tracked by Trend Micro as Water Tambanakua and by Unit 42 as Slippery Scorpius, and its affiliates have been linked to high-profile intrusions including the 2025 attacks on UK retailers. The operation shares a name with DragonForce Malaysia, a pro-Palestine hacktivist collective active from 2021, but no conclusive link between the two has been established — Trend Micro and Group-IB describe the connection as unproven, Trustwave SpiderLabs calls the claims unsubstantiated, and DragonForce Malaysia has publicly denied involvement in ransomware. No country of origin is attributed.

Also tracked as

Water Tambanakua, Slippery Scorpius, DragonForce Ransomware Cartel

IntelFusions coverage (13)

Tools & malware

Recent claimed victims

Vendor research

Read the full analysis on IntelFusions