Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Cybercrime

DragonForce: the cartel that absorbed its rivals

Jesse William McGrawBy Jesse William McGrawJuly 17, 2026Updated:July 18, 2026No Comments4 Mins Read75 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
DragonForce: the cartel that absorbed its rivals, ransomnews.com
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

DragonForce is the ransomware operation that tried to turn itself into a cartel. Active since 2023, it rebranded around a white-label model, letting affiliates run attacks under their own names on DragonForce infrastructure, and positioned itself to absorb rivals, most notably claiming that RansomHub affiliates migrated to its platform after RansomHub vanished in April 2025. It was tied to major UK retail attacks in early 2025 and continued a quieter global run into 2026, though its victim volume fell to around 27 in the second quarter. Its story is consolidation, not raw growth.

Who is DragonForce?

DragonForce is a ransomware group first seen in 2023 that reinvented itself as a self-styled cartel offering affiliates white-label ransomware and infrastructure. Rather than competing purely on victim count, it competes on being the platform other operators build on. It has shifted toward data-theft extortion over pure encryption and publicly prohibits targeting healthcare, framing itself as a business rather than a wrecking crew. See the wider ecosystem in the Ransomnews threat-group catalogue.

The cartel model, explained

The cartel framing is what makes DragonForce distinctive. Under white-labeling, an affiliate can deploy ransomware branded as their own while relying on DragonForce for the encryptor, leak site, and negotiation infrastructure. That lowers the barrier for smaller operators and lets DragonForce take a cut across many brands. When RansomHub disappeared in April 2025, DragonForce claimed its affiliates moved over, an absorption play that grows the platform without DragonForce running every attack itself.

DRAGONFORCE // CARTEL WHITE-LABEL MODEL DRAGONFORCEencryptor, leak site, infra AFFILIATE Aown brand EX-RANSOMHUBmigrated 2025 AFFILIATE Cown brand Tactics: BYOVD, Microsoft Teams as C2, data-theft extortion. No healthcare targeting. Q2 2026 volume: ~27 victims (down from peak) | UK retail hits: early 2025

What has DragonForce attacked?

DragonForce drew wide attention for a wave of UK retail attacks in early 2025, with major high-street names reported among the victims, and for targeting managed service providers and remote-management tooling to reach many downstream organizations at once. Into June 2026 it kept a quieter but global run of victims across Europe, Asia, and the Middle East. Its second-quarter 2026 volume, around 27 victims by one tracker, is well down from its peak, reflecting a shift from headline-grabbing sprees to steadier platform operation.

What are DragonForce’s tactics?

DragonForce affiliates use bring-your-own-vulnerable-driver techniques to disable endpoint defenses and have abused Microsoft Teams as a command-and-control channel, blending into legitimate collaboration traffic. The operational emphasis has moved toward data theft and extortion rather than always encrypting, which lets affiliates monetize even where encryption would be blocked or recoverable. The self-imposed no-healthcare rule is a reputational and legal calculation as much as an ethical one.

How to defend against DragonForce

Because DragonForce operates through many affiliate brands, defend against the techniques rather than the label. Monitor for unexpected Microsoft Teams activity that could indicate command-and-control abuse, enable the vulnerable-driver blocklist to blunt BYOVD, and scrutinize managed-service and remote-management access, a favored path to many victims through one compromise. Given the data-theft emphasis, assume exfiltration in any intrusion and plan notification accordingly. Offline backups remain essential where encryption is used.

Frequently asked questions

What is DragonForce?

DragonForce is a ransomware group active since 2023 that rebranded as a cartel offering affiliates white-label ransomware and infrastructure, taking a cut across many operator brands.

Did DragonForce absorb RansomHub?

DragonForce claimed that RansomHub affiliates migrated to its platform after RansomHub disappeared in April 2025, an absorption that expands the cartel without DragonForce running every attack.

Did DragonForce attack UK retailers?

DragonForce was tied to a wave of major UK retail attacks in early 2025, one of the incidents that raised its profile before its 2026 volume declined.

Does DragonForce attack hospitals?

DragonForce publicly prohibits targeting healthcare, a reputational and legal stance it frames as running a business rather than causing indiscriminate harm.

What tactics does DragonForce use?

Its affiliates use BYOVD to disable EDR, abuse Microsoft Teams for command and control, and emphasize data-theft extortion, often through managed-service and remote-management access.

Sources and further reading

  • Dark Reading: DragonForce cartel profits from rivals’ demise
  • LevelBlue SpiderLabs: Inside DragonForce’s cartel ambitions
  • ReliaQuest: Ransomware and cyber extortion in Q2 2026 (July 16, 2026)
  • Ransomnews threat-group catalogue
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleShinyHunters’ Salesforce extortion wave hits Fluke, Ingram
Next Article GodDamn ransomware blinds EDR with a Microsoft-signed driver
Jesse William McGraw

Jesse William McGraw, also known as GhostExodus, is a former insider threat and threat actor. He became the first person in recent U.S. history to be convicted of corrupting industrial control systems. Today he focuses on threat intelligence, OSINT, and public speaking, using his knowledge to bring awareness to the security risks that organisations and individuals face.

Related Posts

Deadlock: ransomware that hides its C2 on the blockchain

July 18, 2026

Clover Health discloses social-engineering breach in 8-K

July 18, 2026

ShinyHunters’ Salesforce extortion wave hits Fluke, Ingram

July 17, 2026

Comments are closed.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.