DragonForce — Ransomware Profile
DragonForce is a ransomware-as-a-service operation first observed in August 2023, initially deploying a variant of the leaked LockBit 3.0 builder and later a customised Conti V3 payload, and rebranding as a ransomware "cartel" in 2025. It is tracked by Trend Micro as Water Tambanakua and by Unit 42 as Slippery Scorpius, and its affiliates have been linked to high-profile intrusions including the 2025 attacks on UK retailers. The operation shares a name with DragonForce Malaysia, a pro-Palestine hacktivist collective active from 2021, but no conclusive link between the two has been established — Trend Micro and Group-IB describe the connection as unproven, Trustwave SpiderLabs calls the claims unsubstantiated, and DragonForce Malaysia has publicly denied involvement in ransomware. No country of origin is attributed.Also tracked as
Water Tambanakua, Slippery Scorpius, DragonForce Ransomware Cartel
IntelFusions coverage (13)
- Critical Citrix NetScaler bug lets attackers bypass login 2026-08-19 · Vulnerabilities
- Citrix NetScaler bug lets attackers hijack VPN gateways 2026-08-14 · Vulnerabilities
- Ransomware claims against Indian firms tripled in a month 2026-08-12 · Cyber Incidents
- Ransomware crews hit Southeast Asian hotels, not hospitals 2026-08-09 · Cyber Incidents
- Ransomware hits Brazil's schools using stolen logins 2026-08-03 · Cyber Incidents
- Interlock ransomware claims a DC housing agency and a refugee charity 2026-07-17 · Ransomware
- DragonForce ransomware posts more than 20 victims in three days 2026-07-17 · Ransomware
- Ransomware crew D1R claims Synopsys breach reaching ARM and Bosch 2026-07-14 · Ransomware
- Access broker exploits Citrix bug to plant DragonForce ransomware 2026-07-10 · Ransomware
- Scattered Spider is not one gang but a sprawling cybercrime movement 2026-07-07 · Ransomware
- Newer ransomware crews claim diagnostics maker Hologic and an Australian fire service 2026-06-28 · Ransomware
- LockBit 5.0 Cross-Platform Analysis: ChaCha20 Encryption, ESXi VM Shutdown Automation, and Near-Zero VirusTotal Detection 2026-02-16 · Ransomware
- Scattered Spider (UNC3944) 2025: Teleport as Novel C2 Persistence on AWS EC2, STONESTOP/POORTRY BYOVD EDR Termination, and DragonForce Ransomware Partnerships 2026-02-16 · Cyber Incidents
Tools & malware
- AdFind Network Reconnaissance
- Advanced IP Scanner Network Reconnaissance
- Cobalt Strike Post-Exploitation Framework
- LaZagne Credential Harvesting
- MEGA Exfiltration Tool
- Mimikatz Credential Harvesting
- PCHunter Tool
- Process Hacker Tool
- PsExec Remote Execution
- RentDrv2 Tool
- SystemBC Backdoor
- Truesight Tool
Recent claimed victims
- rubbermill.com 2026-09-06
- Homewood Sales 2026-09-06
- Norwood Law Firm 2026-09-06
- Frato 2026-08-24
- Criba 2026-08-24
- Brookview Financial 2026-08-24
- Wozair 2026-08-24
- Hogan Omidi P.C. 2026-08-21
- R & D Machine and Engineering 2026-08-18
- Vermont XCenter 2026-08-17
- GB Group S.A 2026-08-13
- QPC Global 2026-08-11
- Primary Eye Care 2026-08-06
- EduSpa 2026-08-06
- Mike Graham Heating And Air Conditioning 2026-08-05
- P. A. Inc. (Performance Alloys) 2026-08-05
- TUI China 2026-08-03
- Baicizhan 2026-08-03
- MBM Law (Moore Bradley Myers) 2026-07-31
- RUS Industrial 2026-07-31
- Lamont Pridmore 2026-07-31
- Katathani Phuket Beach Resort 2026-07-27
- Syntron Bioresearch 2026-07-26
- Deluxe Medical Supply 2026-07-26
- ID engineering 2026-07-24
Vendor research
- The DragonForce Cartel: Scattered Spider at the gate Acronis
- LOCKBIT Black's Legacy: Unraveling the DragonForce Ransomware Connection Cyble
- DragonForce actors target SimpleHelp vulnerabilities to attack MSP, customers Sophos
- DragonForce targets rivals in a play for dominance Sophos
- Ransomware Spotlight: DragonForce Trend Micro
- Inside the Dragon: DragonForce Ransomware Group Group-IB