DragonForce is the ransomware operation that tried to turn itself into a cartel. Active since 2023, it rebranded around a white-label model, letting affiliates run attacks under their own names on DragonForce infrastructure, and positioned itself to absorb rivals, most notably claiming that RansomHub affiliates migrated to its platform after RansomHub vanished in April 2025. It was tied to major UK retail attacks in early 2025 and continued a quieter global run into 2026, though its victim volume fell to around 27 in the second quarter. Its story is consolidation, not raw growth.
Who is DragonForce?
DragonForce is a ransomware group first seen in 2023 that reinvented itself as a self-styled cartel offering affiliates white-label ransomware and infrastructure. Rather than competing purely on victim count, it competes on being the platform other operators build on. It has shifted toward data-theft extortion over pure encryption and publicly prohibits targeting healthcare, framing itself as a business rather than a wrecking crew. See the wider ecosystem in the Ransomnews threat-group catalogue.
The cartel model, explained
The cartel framing is what makes DragonForce distinctive. Under white-labeling, an affiliate can deploy ransomware branded as their own while relying on DragonForce for the encryptor, leak site, and negotiation infrastructure. That lowers the barrier for smaller operators and lets DragonForce take a cut across many brands. When RansomHub disappeared in April 2025, DragonForce claimed its affiliates moved over, an absorption play that grows the platform without DragonForce running every attack itself.
What has DragonForce attacked?
DragonForce drew wide attention for a wave of UK retail attacks in early 2025, with major high-street names reported among the victims, and for targeting managed service providers and remote-management tooling to reach many downstream organizations at once. Into June 2026 it kept a quieter but global run of victims across Europe, Asia, and the Middle East. Its second-quarter 2026 volume, around 27 victims by one tracker, is well down from its peak, reflecting a shift from headline-grabbing sprees to steadier platform operation.
What are DragonForce’s tactics?
DragonForce affiliates use bring-your-own-vulnerable-driver techniques to disable endpoint defenses and have abused Microsoft Teams as a command-and-control channel, blending into legitimate collaboration traffic. The operational emphasis has moved toward data theft and extortion rather than always encrypting, which lets affiliates monetize even where encryption would be blocked or recoverable. The self-imposed no-healthcare rule is a reputational and legal calculation as much as an ethical one.
How to defend against DragonForce
Because DragonForce operates through many affiliate brands, defend against the techniques rather than the label. Monitor for unexpected Microsoft Teams activity that could indicate command-and-control abuse, enable the vulnerable-driver blocklist to blunt BYOVD, and scrutinize managed-service and remote-management access, a favored path to many victims through one compromise. Given the data-theft emphasis, assume exfiltration in any intrusion and plan notification accordingly. Offline backups remain essential where encryption is used.
Frequently asked questions
What is DragonForce?
DragonForce is a ransomware group active since 2023 that rebranded as a cartel offering affiliates white-label ransomware and infrastructure, taking a cut across many operator brands.
Did DragonForce absorb RansomHub?
DragonForce claimed that RansomHub affiliates migrated to its platform after RansomHub disappeared in April 2025, an absorption that expands the cartel without DragonForce running every attack.
Did DragonForce attack UK retailers?
DragonForce was tied to a wave of major UK retail attacks in early 2025, one of the incidents that raised its profile before its 2026 volume declined.
Does DragonForce attack hospitals?
DragonForce publicly prohibits targeting healthcare, a reputational and legal stance it frames as running a business rather than causing indiscriminate harm.
What tactics does DragonForce use?
Its affiliates use BYOVD to disable EDR, abuse Microsoft Teams for command and control, and emphasize data-theft extortion, often through managed-service and remote-management access.
