Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors dragonforce

Description

DragonForce is a major ransomware-as-a-service operation first observed in August 2023 that launched a formal affiliate program offering 80% revenue share, then rebranded as a "ransomware cartel" in 2025, gaining notoriety for high-profile attacks on UK retailers Marks & Spencer, Co-op, and Harrods. Known victims: 506 17 negotiation log(s) available, 2 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Countries / Regions

United States of America

AI Analysis

No AI analysis yet.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 13 URL 2 MD5 Hash 5

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

271

Campaigns

38

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
M
Confidence
80%
First Seen
Oct 20, 2022
Last Seen
Aug 10, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.