FlagThis
← Threat Actors
/
Malaysia
/
DragonForce
DOSSIER // DRAGONFORCE
DragonForce
ACTIVE CAMPAIGN TRACKED
⚠ Critical Threat
Malaysia
Primary Aliases:
DFRC
DragonForce Malaysia
DragonForce Ransomware Cartel
G1053
🔍 Adversary Rosetta Stone (6) ▾
📋 Copy All
Sponsor / State Affiliation
Independent / Not Attributed
Primary Motivation
financial gain
Active Timeline
Unknown – Present
Confidence Rating
90% (Grounded)
UK High-Street Retail Campaign, Hybrid Cloud Pivot, US SMB Sector Wave
📥 Export ATT&CK Layer (.json)
🔔 RSS Feed
🏛️ CISA Advisories ↗
📋 Copy Dossier Briefing
⚔️ Weaponized CVE Matrix
(0)
No specific weaponized CVEs currently mapped in the public baseline.
🎯 Target Sectors & Focus
Retail
Manufacturing
Healthcare
Logistics
Technology
Critical National Infrastructure (CNI)
Professional Services
🛡️ MITRE ATT&CK® Attack Lifecycle
(8 TTPs)
📥 Download Navigator JSON
All Stages
8
Persistence & Privilege Escalation
1
Defense Evasion
1
Credential Access & Discovery
2
Command & Control
2
Operational Techniques
2
Persistence & Privilege Escalation
1
T1547
Entra ID (Azure AD) privilege escalation and persistence via malicious federated domains
↗
Defense Evasion
1
T1027
BYOVD (Bring Your Own Vulnerable Driver) using truesight.sys and rentdrv2.sys to disable EDR
↗
Credential Access & Discovery
2
T1003
Vishing and advanced social engineering (via Muddled Libra partnership)
↗
T1003
Post-compromise discovery using AzureHound
↗
Command & Control
2
T1071
Double Extortion (Data Exfiltration + Encryption)
↗
T1071
C2 concealment using Backdoor.Turn via Microsoft Teams TURN relay infrastructure
↗
Operational Techniques
2
T1000
White-label RaaS/Cartel Model
↗
T1000
Cloud-native extortion (deletion of Azure backups and data without endpoint encryptors)
↗
📰 Verified Campaigns & Intelligence Archive
🔔 Subscribe to Alerts
[DEEP DIVE]
Dragonforce Ransomware Group Abuses Microsoft Teams for C2 in Aptora Intrusion
Attacks and Vulnerabilities
2026-06-28
Adversary Rosetta Stone // DragonForce
×
🛡️ Other Industry Tracking Codes
DFRC
📋
DragonForce Malaysia
📋
DragonForce Ransomware Cartel
📋
G1053
📋
Slippery Scorpius
📋
Storm-0501
📋
Copied to clipboard
SHARE INTELLIGENCE WIRE
×
Story Title
X / Twitter
Bluesky
LinkedIn
Copy Link
LINK COPIED TO CLIPBOARD