DragonForce Ransomware

Description Summary

DragonForce is a ransomware-as-a-service that emerged in late 2023, originally leveraging a leaked LockBit Black builder. In 2024–2025 it positioned itself as a 'cartel,' offering affiliates the ability to use the DragonForce platform while running their own brand. Scattered Spider has used DragonForce in attacks on UK retailers including Marks & Spencer and Co-op in 2025.

Threat Actor

RaaS with broad affiliate base; recently adopted by Scattered Spider.

Technical Indicators

Encryption Extension
.dragonforce_encrypted
Encryption Algorithm
AES-256 + RSA (LockBit Black-derived)
Ransom Note Name
readme.txt
Targeted Industries
Retail, Education, Government, Manufacturing
First Seen
December 2023
Last Seen
Active
Geographical Location
Global; high-profile UK retail impact in 2025

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 3 T1566 Phishing
T1190 Exploit Public-Facing Application
T1078 Valid Accounts
Execution x 1 T1059 Command and Scripting Interpreter
Execution Persistence x 1 T1053 Scheduled Task/Job
Defense Evasion x 2 T1562.001 Disable or Modify Tools
T1070.004 File Deletion
Discovery x 2 T1083 File and Directory Discovery
T1082 System Information Discovery
Lateral Movement x 2 T1021.001 Remote Services: RDP
T1021.002 SMB/Windows Admin Shares
Exfiltration x 2 T1041 Exfiltration Over C2 Channel
T1567.002 Exfiltration to Cloud Storage
Impact x 3 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop